Vulnerabilities > CVE-2007-4305 - System Call Wrappers Concurrency vulnerability in Systrace
Attack vector
LOCAL Attack complexity
HIGH Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.
Vulnerable Configurations
Exploit-Db
description | Systrace Multiple System Call Wrappers Concurrency Vulnerabilities. CVE-2007-4305. Local exploit for bsd platform |
id | EDB-ID:30484 |
last seen | 2016-02-03 |
modified | 2007-08-09 |
published | 2007-08-09 |
reporter | Robert N. M. Watson |
source | https://www.exploit-db.com/download/30484/ |
title | Systrace Multiple System Call Wrappers Concurrency Vulnerabilities |