VulnerabilityModified
CVE-2005-4782
NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.
MEDIUM 4.9EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- netbsd/netbsd
- Source
- cve@mitre.org
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/kern/uipc_socket.c.diff?r1=1.111&r2=1.112Patch
- http://mail-index.netbsd.org/netbsd-announce/2005/11/08/0010.htmlPatch
- http://mail-index.netbsd.org/source-changes/2005/10/21/0038.htmlPatch
- http://www.securityfocus.com/bid/15289
- http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/kern/uipc_socket.c.diff?r1=1.111&r2=1.112Patch
- http://mail-index.netbsd.org/netbsd-announce/2005/11/08/0010.htmlPatch
- http://mail-index.netbsd.org/source-changes/2005/10/21/0038.htmlPatch
- http://www.securityfocus.com/bid/15289
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.