Lucene search

K
cve[email protected]CVE-2004-1066
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1066

2005-01-1005:00:00
web.nvd.nist.gov
19
cve-2004-1066
freebsd
denial of service
kernel memory
local users
procfs
linprocfs

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:N/A:P

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future.

Affected configurations

NVD
Node
freebsdfreebsdMatch4.0
OR
freebsdfreebsdMatch4.1
OR
freebsdfreebsdMatch4.1.1
OR
freebsdfreebsdMatch4.2
OR
freebsdfreebsdMatch4.3
OR
freebsdfreebsdMatch4.4
OR
freebsdfreebsdMatch4.5
OR
freebsdfreebsdMatch4.6
OR
freebsdfreebsdMatch4.7
OR
freebsdfreebsdMatch4.8
OR
freebsdfreebsdMatch4.8releng
OR
freebsdfreebsdMatch4.9
OR
freebsdfreebsdMatch4.10
OR
freebsdfreebsdMatch4.10release
OR
freebsdfreebsdMatch4.10releng
OR
freebsdfreebsdMatch5.0
OR
freebsdfreebsdMatch5.1
OR
freebsdfreebsdMatch5.2
OR
freebsdfreebsdMatch5.2.1release
OR
freebsdfreebsdMatch5.2.1releng
OR
freebsdfreebsdMatch5.3
OR
freebsdfreebsdMatch5.3release
OR
freebsdfreebsdMatch5.3stable

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:N/A:P

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%