PT-2002-1980 · Freebsd · Freebsd
Publicado
2002-08-23
·
Atualizado
2016-10-18
·
CVE-2002-0973
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
FreeBSD versions 4.6.1 RELEASE-p10 and earlier
Description:
The issue is related to an integer signedness error in several system calls, which may allow attackers to access sensitive kernel memory. This can be achieved by providing large negative values to specific system calls, including the
accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.Recommendations:
For FreeBSD versions 4.6.1 RELEASE-p10 and earlier, consider restricting access to the affected system calls until a patch is available. As a temporary workaround, avoid using large negative values in the
accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Freebsd