CVE-1999-1214

The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
Configurations

Configuration 1 (hide)

cpe:2.3:o:sgi:irix:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:bsd:bsd:*:*:*:*:*:*:*:*
cpe:2.3:o:bsd:bsd:4.4:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:stable:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:2.0.4:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:2.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:30

Type Values Removed Values Added
References () http://www.openbsd.com/advisories/signals.txt - () http://www.openbsd.com/advisories/signals.txt -
References () http://www.osvdb.org/11062 - () http://www.osvdb.org/11062 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/556 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/556 -

Information

Published : 1997-09-15 04:00

Updated : 2024-11-20 23:30


NVD link : CVE-1999-1214

Mitre link : CVE-1999-1214

CVE.ORG link : CVE-1999-1214


JSON object : View

Products Affected

openbsd

  • openbsd

sgi

  • irix

netbsd

  • netbsd

bsd

  • bsd

freebsd

  • freebsd
CWE
CWE-255

Credentials Management Errors