Vulnerabilities > CVE-2004-2012 - Privilege Escalation vulnerability in NetBSD/FreeBSD Port Systrace Exit Routine Access Validation

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
niels
vladimir-kotal
netbsd
exploit available

Summary

The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.

Exploit-Db

descriptionNetBSD/FreeBSD Port Systrace 1.x Exit Routine Access Validation Privilege Escalation Vulnerability. CVE-2004-2012. Local exploit for bsd platform
idEDB-ID:24113
last seen2016-02-02
modified2004-05-11
published2004-05-11
reporterStefan Esser
sourcehttps://www.exploit-db.com/download/24113/
titleNetBSD/FreeBSD Port Systrace 1.x - Exit Routine Access Validation Privilege Escalation Vulnerability