PT-2020-9765 · Freebsd · Freebsd
Published
2020-03-19
·
Updated
2021-07-21
·
CVE-2019-15877
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 12.1-STABLE before r356606
FreeBSD versions 12.1-RELEASE before 12.1-RELEASE-p3
Description
The issue arises from driver specific ioctl command handlers in the ixl network driver that failed to check whether the caller has sufficient privileges. This allows unprivileged users to trigger updates to the device's non-volatile memory.
Recommendations
For FreeBSD versions 12.1-STABLE before r356606, update to a version after r356606 to resolve the issue.
For FreeBSD versions 12.1-RELEASE before 12.1-RELEASE-p3, update to 12.1-RELEASE-p3 or later to resolve the issue.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd