VYPR

systrace

by NetBSD

CVEs (2)

  • CVE-2007-4305Aug 13, 2007
    risk 0.03cvss epss 0.01

    Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.

  • CVE-2004-2012Dec 31, 2004
    risk 0.03cvss epss 0.01

    The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.