PT-2014-5572 · Freebsd · Freebsd

Published

2014-06-10

·

Updated

2014-06-21

·

CVE-2014-3880

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD kernel versions prior to 8.4 p11 FreeBSD kernel versions prior to 9.1 p14 FreeBSD kernel versions prior to 9.2 p7 FreeBSD kernel versions prior to 10.0 p4
Description The issue allows local users to cause a denial of service, resulting in a system reboot, by triggering an invalid page table pointer dereference via a crafted system call. This occurs because the execve and fexecve system calls destroy the virtual memory address space and mappings for a process before all threads have terminated.
Recommendations For FreeBSD kernel version 8.4, update to at least p11 to resolve the issue. For FreeBSD kernel version 9.1, update to at least p14 to resolve the issue. For FreeBSD kernel version 9.2, update to at least p7 to resolve the issue. For FreeBSD kernel version 10.0, update to at least p4 to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3880
DSA-2952-1

Affected Products

Freebsd