PT-2002-1980 · Freebsd · Freebsd
Published
2002-08-23
·
Updated
2016-10-18
·
CVE-2002-0973
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
FreeBSD versions 4.6.1 RELEASE-p10 and earlier
Description:
The issue is related to an integer signedness error in several system calls, which may allow attackers to access sensitive kernel memory. This can be achieved by providing large negative values to specific system calls, including the
accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.Recommendations:
For FreeBSD versions 4.6.1 RELEASE-p10 and earlier, consider restricting access to the affected system calls until a patch is available. As a temporary workaround, avoid using large negative values in the
accept, getsockname, and getpeername system calls, as well as the vesa FBIO GETPALETTE ioctl.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd