PT-2019-17774 · Freebsd · Freebsd
Published
2019-07-24
·
Updated
2023-03-01
·
CVE-2019-5605
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 11.2-RELEASE before 11.2-RELEASE-p12
FreeBSD versions 11.3-RELEASE before 11.3-RELEASE-p1
FreeBSD versions 11.3-STABLE before r350217
Description
The issue is related to insufficient initialization of memory copied to userland in the freebsd32 ioctl interface. This may cause small amounts of kernel memory to be disclosed to userland processes, potentially allowing an attacker to leverage this information to obtain elevated privileges.
Recommendations
For FreeBSD versions 11.2-RELEASE before 11.2-RELEASE-p12, update to 11.2-RELEASE-p12 or later.
For FreeBSD versions 11.3-RELEASE before 11.3-RELEASE-p1, update to 11.3-RELEASE-p1 or later.
For FreeBSD versions 11.3-STABLE before r350217, update to r350217 or later.
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd