4.9

CVE-2009-1935

Exploit

Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version6.3
FreebsdFreebsd Version6.3 Updaterelease_p10
FreebsdFreebsd Version6.3_releng
FreebsdFreebsd Version6.4
FreebsdFreebsd Version6.4 Updaterelease_p4
FreebsdFreebsd Version6.4 Updatestable
FreebsdFreebsd Version7.1
FreebsdFreebsd Version7.1 Updatepre-release
FreebsdFreebsd Version7.1 Updaterc1
FreebsdFreebsd Version7.1 Updaterelease-p1
FreebsdFreebsd Version7.1 Updaterelease-p2
FreebsdFreebsd Version7.1 Updaterelease-p5
FreebsdFreebsd Version7.1 Updatestable
FreebsdFreebsd Version7.2
FreebsdFreebsd Version7.2 Updatepre-release
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.184
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:C/I:N/A:N