Search

published date: July 5, 2005

CVE-2005-2134 : Denial of Service Vulnerability

Description

The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.

Product(s):

  • NetBSD 1.6.1
  • NetBSD 1.6.2
  • NetBSD 1.6
  • NetBSD 1.6 Beta
  • NetBSD 2.0.1
  • NetBSD 2.0.2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-2134, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-2134 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?