PT-2002-1980 · Freebsd · Freebsd

Publicado

2002-08-23

·

Atualizado

2016-10-18

·

CVE-2002-0973

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: FreeBSD versions 4.6.1 RELEASE-p10 and earlier
Description: The issue is related to an integer signedness error in several system calls, which may allow attackers to access sensitive kernel memory. This can be achieved by providing large negative values to specific system calls, including the accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.
Recommendations: For FreeBSD versions 4.6.1 RELEASE-p10 and earlier, consider restricting access to the affected system calls until a patch is available. As a temporary workaround, avoid using large negative values in the accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0973

Produtos afetados

Freebsd