PT-2005-2397 · Freebsd · Freebsd
Published
2005-05-06
·
Updated
2008-09-05
·
CVE-2005-1400
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
FreeBSD versions 4.7 through 4.11
FreeBSD versions 5.x through 5.4
Description:
The issue allows local users to access sensitive kernel memory. This is achieved by utilizing the i386 get ldt system call with arguments that have negative or very large values.
Recommendations:
For FreeBSD versions 4.7 through 4.11, update to a version outside of this range to resolve the issue.
For FreeBSD versions 5.x through 5.4, update to a version outside of this range to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd