PT-2008-4915 · Freebsd · Freebsd

James Gritton

·

Published

2008-09-05

·

Updated

2017-08-08

·

CVE-2008-3531

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 7.0 through 7.1
Description A stack-based buffer overflow issue exists in the kernel, specifically in sys/kern/vfs mount.c, when vfs.usermount is enabled. This allows local users to gain privileges via a crafted mount or nmount system call. The issue is related to the copying of user-defined data in certain error conditions.
Recommendations For FreeBSD versions 7.0 through 7.1, consider disabling the vfs.usermount option as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3531

Affected Products

Freebsd