PT-2005-2962 · Freebsd · Freebsd

Publicado

2005-06-30

·

Atualizado

2008-09-05

·

CVE-2005-2019

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD version 5.4
Description The issue is related to the ipfw component in FreeBSD, specifically when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled. It does not properly lock certain resources during table lookups, which can lead to corrupted cache results when multiple lookups occur concurrently. This can allow remote attackers to bypass intended access restrictions.
Recommendations For FreeBSD version 5.4, consider disabling the PREEMPTION kernel option as a temporary workaround to minimize the risk of exploitation. Restrict access to the ipfw component to minimize the risk of bypassing intended access restrictions.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2019

Produtos afetados

Freebsd