Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.

Project Subscriptions

Vendors Products
Openbsd Subscribe
Openbsd Subscribe
Sysjail Subscribe
Sysjail Subscribe
Systrace Subscribe
Systrace Subscribe
Todd Miller Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2007-4288 Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T14:53:55.846Z

Reserved: 2007-08-13T04:00:00.000Z

Link: CVE-2007-4305

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-08-13T21:17:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-4305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses