|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 4.3-STABLE or the RELENG_4_3 security branch, dated after the respective correction dates, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): unmount all instances of the procfs and linprocfs filesystems.
#umount -f -a -t procfs #umount -f -a -t linprocfs
|
|
Products |
|
FreeBSD
 |
4.0 |
3.5 |
3.5.1 |
4.1 |
4.1.1 |
4.2 |
4.3 |
|
|
|
|
Credit |
- Joost Pol - joost
contempt.nl - Laberatoire Contempt
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|