Lucene search

K
cve[email protected]CVE-2003-1289
HistoryDec 17, 2005 - 9:00 p.m.

CVE-2003-1289

2005-12-1721:00:00
web.nvd.nist.gov
20
netbsd
freebsd
statfs
memory disclosure
ibcs2
cve-2003-1289

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.

Affected configurations

NVD
Node
freebsdfreebsdRange4.8release_p2
OR
freebsdfreebsdRange5.1release_p1
OR
freebsdfreebsdMatch4.0
OR
freebsdfreebsdMatch5.0
OR
netbsdnetbsdMatch1.5
OR
netbsdnetbsdMatch1.5.1
OR
netbsdnetbsdMatch1.5.2
OR
netbsdnetbsdMatch1.5.3

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2003-1289