PT-2019-4135 · Freebsd · Freebsd
Karsten Kã¶Nig
·
Published
2019-07-23
·
Updated
2023-03-29
·
CVE-2019-5603
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions prior to 12.0-RELEASE-p8
FreeBSD versions prior to 11.3-RELEASE-p1
FreeBSD versions prior to 11.2-RELEASE-p12
Description
The issue is related to the mqueuefs module in FreeBSD, which has inadequate access control. This allows a malicious user to potentially gain unauthorized access to files, directories, and sockets opened by other users' processes.
Recommendations
For versions prior to 12.0-RELEASE-p8, update to 12.0-RELEASE-p8 or later.
For versions prior to 11.3-RELEASE-p1, update to 11.3-RELEASE-p1 or later.
For versions prior to 11.2-RELEASE-p12, update to 11.2-RELEASE-p12 or later.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd