The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/17312 | vdb entry patch vendor advisory |
http://www.osvdb.org/24262 | vdb entry |
http://secunia.com/advisories/19464 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25582 | vdb entry |
ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc | vendor advisory |
http://securitytracker.com/id?1015846 | vdb entry patch |