Vulnerabilities > CVE-2007-1189 - Local Integer Overflow vulnerability in Plan 9

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
bell-labs
exploit available

Summary

Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.

Vulnerable Configurations

Part Description Count
OS
Bell_Labs
1

Exploit-Db

descriptionPlan 9 Kernel (devenv.c OTRUNC/pwrite) Local Exploit. CVE-2007-1189. Local exploit for plan9 platform
fileexploits/plan9/local/3383.c
idEDB-ID:3383
last seen2016-01-31
modified2007-02-28
platformplan9
port
published2007-02-28
reporterDon Bailey
sourcehttps://www.exploit-db.com/download/3383/
titlePlan 9 Kernel devenv.c OTRUNC/pwrite Local Exploit
typelocal