CVE-2003-0955
CVE-2003-0955
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/118unverifiedexploitdbwww.exploit-db.com/exploits/125unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patchhttp://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013315.htmlhttp://marc.info/?l=openbsd-security-announce&m=106808820119679&w=2http://marc.info/?l=openbsd-security-announce&m=106917441524978&w=2http://www.guninski.com/msuxobsd2.htmlhttp://www.openbsd.org/errata33.htmlhttp://www.securityfocus.com/bid/8978