PT-2014-5632 · Freebsd · Freebsd

Published

2014-07-15

·

Updated

2014-11-19

·

CVE-2014-3953

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 8.4 before p14 FreeBSD versions 9.1 before p17 FreeBSD versions 9.2 before p10 FreeBSD versions 10.0 before p7
Description The issue allows local users to obtain sensitive information from kernel memory. This can be achieved via certain SCTP cmsg or notifications, including SCTP SNDRCV, SCTP EXTRCV, SCTP RCVINFO, SCTP PEER ADDR CHANGE, SCTP REMOTE ERROR, or SCTP AUTHENTICATION EVENT.
Recommendations For FreeBSD version 8.4, update to p14 or later. For FreeBSD version 9.1, update to p17 or later. For FreeBSD version 9.2, update to p10 or later. For FreeBSD version 10.0, update to p7 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3953
DSA-3070-1

Affected Products

Freebsd