[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1436Date: (C)2009-04-27   (M)2023-12-22


The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.9
Exploit Score: 3.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1022113
BID-34666
SECUNIA-34810
OSVDB-53918
FreeBSD-SA-09:07
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10756

CPE    4
cpe:/o:freebsd:freebsd:7.0
cpe:/o:freebsd:freebsd:7.1
cpe:/o:freebsd:freebsd:6.3
cpe:/o:freebsd:freebsd:6.4
...
CWE    1
CWE-20

© SecPod Technologies