PT-2002-1980 · Freebsd · Freebsd

Published

2002-08-23

·

Updated

2016-10-18

·

CVE-2002-0973

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: FreeBSD versions 4.6.1 RELEASE-p10 and earlier
Description: The issue is related to an integer signedness error in several system calls, which may allow attackers to access sensitive kernel memory. This can be achieved by providing large negative values to specific system calls, including the accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.
Recommendations: For FreeBSD versions 4.6.1 RELEASE-p10 and earlier, consider restricting access to the affected system calls until a patch is available. As a temporary workaround, avoid using large negative values in the accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0973

Affected Products

Freebsd