PT-2004-1572 · Freebsd · Freebsd
Published
2004-06-03
·
Updated
2017-07-11
·
CVE-2004-0435
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions prior to 5.2.1
FreeBSD versions 4.10 and earlier
Description
The issue arises from certain programming errors in the msync system call, specifically with handling the MS INVALIDATE operation. This leads to cache consistency problems, allowing a local user to prevent certain file changes from being committed to disk.
Recommendations
For versions prior to 5.2.1, update to a version that properly handles the MS INVALIDATE operation in the msync system call.
For versions 4.10 and earlier, update to a version that properly handles the MS INVALIDATE operation in the msync system call.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd