Lucene search

K
cve[email protected]CVE-2009-2208
HistoryJun 25, 2009 - 2:00 a.m.

CVE-2009-2208

2009-06-2502:00:00
CWE-264
web.nvd.nist.gov
15
cve-2009-2208
freebsd
permissions
siocsifinfo_in6
ioctl
ipv6
network interfaces
mtu

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.

Affected configurations

NVD
Node
freebsdfreebsdMatch6.3
OR
freebsdfreebsdMatch6.3release_p10
OR
freebsdfreebsdMatch6.3release_p11
OR
freebsdfreebsdMatch6.3release_p6
OR
freebsdfreebsdMatch6.3release_p8
OR
freebsdfreebsdMatch6.3release_p9
OR
freebsdfreebsdMatch6.3_releng
OR
freebsdfreebsdMatch6.4
OR
freebsdfreebsdMatch6.4release
OR
freebsdfreebsdMatch6.4release_p2
OR
freebsdfreebsdMatch6.4release_p3
OR
freebsdfreebsdMatch6.4release_p4
OR
freebsdfreebsdMatch6.4release_p5
OR
freebsdfreebsdMatch6.4stable
OR
freebsdfreebsdMatch7.1
OR
freebsdfreebsdMatch7.1pre-release
OR
freebsdfreebsdMatch7.1rc1
OR
freebsdfreebsdMatch7.1release-p1
OR
freebsdfreebsdMatch7.1release-p2
OR
freebsdfreebsdMatch7.1release-p4
OR
freebsdfreebsdMatch7.1release-p5
OR
freebsdfreebsdMatch7.1release-p6
OR
freebsdfreebsdMatch7.1stable
OR
freebsdfreebsdMatch7.2
OR
freebsdfreebsdMatch7.2pre-release
OR
freebsdfreebsdMatch7.2stable

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2009-2208