7.5

CVE-2024-6760

ktrace(2) fails to detach when executing a setuid binary

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.

The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version < 13.0
Freebsd ≫ Freebsd Version >= 13.1 < 13.3
Freebsd ≫ Freebsd Version 13.3 Update p1
Freebsd ≫ Freebsd Version 13.3 Update p2
Freebsd ≫ Freebsd Version 13.3 Update p3
Freebsd ≫ Freebsd Version 13.3 Update p4
Freebsd ≫ Freebsd Version 14.0 Update beta5
Freebsd ≫ Freebsd Version 14.0 Update p1
Freebsd ≫ Freebsd Version 14.0 Update p2
Freebsd ≫ Freebsd Version 14.0 Update p3
Freebsd ≫ Freebsd Version 14.0 Update p4
Freebsd ≫ Freebsd Version 14.0 Update p5
Freebsd ≫ Freebsd Version 14.0 Update p6
Freebsd ≫ Freebsd Version 14.0 Update p7
Freebsd ≫ Freebsd Version 14.0 Update p8
Freebsd ≫ Freebsd Version 14.0 Update rc3
Freebsd ≫ Freebsd Version 14.0 Update rc4-p1
Freebsd ≫ Freebsd Version 14.1 Update p1
Freebsd ≫ Freebsd Version 14.1 Update p2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://security.freebsd.org/advisories/FreeBSD-SA-24:06.ktrace.asc
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240816-0010/