PT-2007-5491 · Cerbng · Cerbng
Robert N. M. Watson
·
Published
2007-08-13
·
Updated
2008-09-05
·
CVE-2007-4303
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CerbNG for FreeBSD version 4.8
Description
The issue involves multiple race conditions found in certain rules and argument copying during VM protection. This could allow local users to defeat system call interposition and possibly gain privileges or bypass auditing. An example of exploitation includes modifying command lines in log-exec.cb.
Recommendations
For CerbNG for FreeBSD version 4.8, consider disabling the affected rules and argument copying during VM protection as a temporary workaround until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cerbng