PT-2014-5572 · Freebsd · Freebsd
Published
2014-06-10
·
Updated
2014-06-21
·
CVE-2014-3880
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD kernel versions prior to 8.4 p11
FreeBSD kernel versions prior to 9.1 p14
FreeBSD kernel versions prior to 9.2 p7
FreeBSD kernel versions prior to 10.0 p4
Description
The issue allows local users to cause a denial of service, resulting in a system reboot, by triggering an invalid page table pointer dereference via a crafted system call. This occurs because the
execve and fexecve system calls destroy the virtual memory address space and mappings for a process before all threads have terminated.Recommendations
For FreeBSD kernel version 8.4, update to at least p11 to resolve the issue.
For FreeBSD kernel version 9.1, update to at least p14 to resolve the issue.
For FreeBSD kernel version 9.2, update to at least p7 to resolve the issue.
For FreeBSD kernel version 10.0, update to at least p4 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd