PT-2005-2962 · Freebsd · Freebsd

Published

2005-06-30

·

Updated

2008-09-05

·

CVE-2005-2019

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD version 5.4
Description The issue is related to the ipfw component in FreeBSD, specifically when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled. It does not properly lock certain resources during table lookups, which can lead to corrupted cache results when multiple lookups occur concurrently. This can allow remote attackers to bypass intended access restrictions.
Recommendations For FreeBSD version 5.4, consider disabling the PREEMPTION kernel option as a temporary workaround to minimize the risk of exploitation. Restrict access to the ipfw component to minimize the risk of bypassing intended access restrictions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2019

Affected Products

Freebsd