4.9

CVE-2009-1436

Exploit
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 6.3
Freebsd ≫ Freebsd Version 6.3 Update release_p10
Freebsd ≫ Freebsd Version 6.4
Freebsd ≫ Freebsd Version 6.4 Update release_p4
Freebsd ≫ Freebsd Version 6.4 Update stable
Freebsd ≫ Freebsd Version 7.0
Freebsd ≫ Freebsd Version 7.0 Update release-p12
Freebsd ≫ Freebsd Version 7.1
Freebsd ≫ Freebsd Version 7.1 Update release-p5
Freebsd ≫ Freebsd Version 7.2 Update pre-release
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.547
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:C/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10756
http://osvdb.org/53918
http://secunia.com/advisories/34810
Vendor Advisory
http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc
Vendor Advisory
http://www.securityfocus.com/bid/34666
Patch
Exploit
http://www.securitytracker.com/id?1022113