4.9

CVE-2009-1935

Exploit
Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 6.3
Freebsd ≫ Freebsd Version 6.3 Update release_p10
Freebsd ≫ Freebsd Version 6.3_releng
Freebsd ≫ Freebsd Version 6.4
Freebsd ≫ Freebsd Version 6.4 Update release_p4
Freebsd ≫ Freebsd Version 6.4 Update stable
Freebsd ≫ Freebsd Version 7.1
Freebsd ≫ Freebsd Version 7.1 Update pre-release
Freebsd ≫ Freebsd Version 7.1 Update rc1
Freebsd ≫ Freebsd Version 7.1 Update release-p1
Freebsd ≫ Freebsd Version 7.1 Update release-p2
Freebsd ≫ Freebsd Version 7.1 Update release-p5
Freebsd ≫ Freebsd Version 7.1 Update stable
Freebsd ≫ Freebsd Version 7.2
Freebsd ≫ Freebsd Version 7.2 Update pre-release
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.346
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:C/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/55044
http://secunia.com/advisories/35398
Vendor Advisory
http://security.freebsd.org/advisories/FreeBSD-SA-09:09.pipe.asc
Patch
Vendor Advisory
http://security.freebsd.org/patches/SA-09:09/pipe.patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/35279
http://www.securitytracker.com/id?1022365
https://exchange.xforce.ibmcloud.com/vulnerabilities/51109