The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allocattr function.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/25682 | vdb entry |
http://www.securitytracker.com/id?1018693 | vdb entry |
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-006.txt.asc | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36598 | vdb entry |
http://osvdb.org/40810 | vdb entry |