Lucene search

K
cveFreebsdCVE-2019-5605
HistoryJul 26, 2019 - 1:15 a.m.

CVE-2019-5605

2019-07-2601:15:10
CWE-665
freebsd
web.nvd.nist.gov
236
cve-2019-5605
freebsd
memory disclosure
userland
privilege escalation

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

57.3%

In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, due to insufficient initialization of memory copied to userland in the freebsd32_ioctl interface, small amounts of kernel memory may be disclosed to userland processes. This may allow an attacker to leverage this information to obtain elevated privileges either directly or indirectly.

Affected configurations

Nvd
Node
freebsdfreebsdMatch11.0-
OR
freebsdfreebsdMatch11.2-
OR
freebsdfreebsdMatch11.2p10
OR
freebsdfreebsdMatch11.2p11
OR
freebsdfreebsdMatch11.2p2
OR
freebsdfreebsdMatch11.2p3
OR
freebsdfreebsdMatch11.2p4
OR
freebsdfreebsdMatch11.2p5
OR
freebsdfreebsdMatch11.2p6
OR
freebsdfreebsdMatch11.2p7
OR
freebsdfreebsdMatch11.2p8
OR
freebsdfreebsdMatch11.2p9
OR
freebsdfreebsdMatch11.2rc3
OR
freebsdfreebsdMatch11.3-
VendorProductVersionCPE
freebsdfreebsd11.0cpe:2.3:o:freebsd:freebsd:11.0:-:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p10:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p11:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p2:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p3:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p4:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p5:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p6:*:*:*:*:*:*
freebsdfreebsd11.2cpe:2.3:o:freebsd:freebsd:11.2:p7:*:*:*:*:*:*
Rows per page:
1-10 of 141

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "status": "affected",
        "version": "FreeBSD 11.x"
      },
      {
        "status": "affected",
        "version": "before 11.3-RELEASE-p1"
      },
      {
        "status": "affected",
        "version": "and before 11.2-RELEASE-p12"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

57.3%