PT-2019-17774 · Freebsd · Freebsd

Published

2019-07-24

·

Updated

2023-03-01

·

CVE-2019-5605

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 11.2-RELEASE before 11.2-RELEASE-p12 FreeBSD versions 11.3-RELEASE before 11.3-RELEASE-p1 FreeBSD versions 11.3-STABLE before r350217
Description The issue is related to insufficient initialization of memory copied to userland in the freebsd32 ioctl interface. This may cause small amounts of kernel memory to be disclosed to userland processes, potentially allowing an attacker to leverage this information to obtain elevated privileges.
Recommendations For FreeBSD versions 11.2-RELEASE before 11.2-RELEASE-p12, update to 11.2-RELEASE-p12 or later. For FreeBSD versions 11.3-RELEASE before 11.3-RELEASE-p1, update to 11.3-RELEASE-p1 or later. For FreeBSD versions 11.3-STABLE before r350217, update to r350217 or later.

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

CVE-2019-5605
FREEBSD-SA-19_14

Affected Products

Freebsd