PT-2002-2127 · Freebsd · Freebsd+1

Publicado

2002-09-17

·

Atualizado

2016-10-18

·

CVE-2002-1125

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: FreeBSD versions prior to 4.6.2-RELEASE asmon versions prior to the fixed version ascpu versions prior to the fixed version bubblemon versions prior to the fixed version wmmon versions prior to the fixed version wmnet2 versions prior to the fixed version
Description: The issue affects FreeBSD port programs that utilize libkvm, allowing local users to read kernel memory due to open file descriptors for /dev/mem and /dev/kmem.
Recommendations: For FreeBSD versions prior to 4.6.2-RELEASE, update to a version that includes the fix for this issue. For asmon, ascpu, bubblemon, wmmon, and wmnet2, update to versions that include the fix for this issue. As a temporary workaround, consider restricting access to /dev/mem and /dev/kmem to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1125

Produtos afetados

Freebsd
Libkvm