[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1066Date: (C)2005-01-10   (M)2023-12-22


The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: PARTIAL
  
Reference:
FreeBSD-SA-04:17
freebsd-profs-linprocfs-info-disclosure(18321)

CPE    16
cpe:/o:freebsd:freebsd:4.1.1
cpe:/o:freebsd:freebsd:4.0
cpe:/o:freebsd:freebsd:4.1
cpe:/o:freebsd:freebsd:5.0
...

© SecPod Technologies