📦

systrace

Vendor: systrace

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.96% Exploit Prob.
Latest CVE CVE-2007-4773 Jan 15

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

Systrace before 1.6.0 has insufficient escape policy enforcement.

EPSS: 1.73%
7.2 CVSS
CVE-2009-0343
Exploit Found

Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.

EPSS: 0.82%
7.2 CVSS

Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.

EPSS: 0.45%
6.2 CVSS
CVE-2007-4305
Exploit Found

Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.

EPSS: 0.86%