Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-3824
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3824

Description:
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27901

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102343-1

ST
  1016555

SAID
  Secunia Advisory: SA21148

MISC
  http://www.idefense.com/intelligence/vulnerabilities/display.php?id=410

IDEFENSE
  http://www.idefense.com/intelligence/vulnerabilities/display.php?id=410

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/440986/100/100/threaded
  http://www.securityfocus.com/archive/1/archive/1/440849/100/100/threaded

BID
  19104


Return to the previous page.