PT-2001-2315 · Freebsd · Freebsd
Publicado
2001-07-10
·
Atualizado
2017-10-10
·
CVE-2001-1180
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD version 4.3
Description
The issue arises from improper clearing of shared signal handlers when executing a process. This allows local users to gain privileges by calling
rfork() with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.Recommendations
For FreeBSD version 4.3, consider updating to a newer version that properly clears shared signal handlers to prevent privilege escalation. As a temporary workaround, restrict the use of setuid programs and shared signal handlers to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Freebsd