Lucene search

K
freebsdFreeBSD0A5CF6D8-600A-11E6-A6C3-14DAE9D210B8
HistoryJan 27, 2015 - 12:00 a.m.

FreeBSD -- SCTP SCTP_SS_VALUE kernel memory corruption and disclosure

2015-01-2700:00:00
vuxml.freebsd.org
15

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

9.8%

Problem Description:
Due to insufficient validation of the SCTP stream ID,
which serves as an array index, a local unprivileged attacker
can read or write 16-bits of kernel memory.
Impact:
An unprivileged process can read or modify 16-bits of
memory which belongs to the kernel. This may lead to
exposure of sensitive information or allow privilege
escalation.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchfreebsd-kernel= 10.1UNKNOWN
FreeBSDanynoarchfreebsd-kernel< 10.1_5UNKNOWN

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

9.8%