CVE Vulnerabilities

CVE-2004-1066

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd4.0 (including)4.0 (including)
FreebsdFreebsd4.1 (including)4.1 (including)
FreebsdFreebsd4.1.1 (including)4.1.1 (including)
FreebsdFreebsd4.2 (including)4.2 (including)
FreebsdFreebsd4.3 (including)4.3 (including)
FreebsdFreebsd4.4 (including)4.4 (including)
FreebsdFreebsd4.5 (including)4.5 (including)
FreebsdFreebsd4.6 (including)4.6 (including)
FreebsdFreebsd4.7 (including)4.7 (including)
FreebsdFreebsd4.8 (including)4.8 (including)
FreebsdFreebsd4.8-releng (including)4.8-releng (including)
FreebsdFreebsd4.9 (including)4.9 (including)
FreebsdFreebsd4.10 (including)4.10 (including)
FreebsdFreebsd4.10-release (including)4.10-release (including)
FreebsdFreebsd4.10-releng (including)4.10-releng (including)
FreebsdFreebsd5.0 (including)5.0 (including)
FreebsdFreebsd5.1 (including)5.1 (including)
FreebsdFreebsd5.2 (including)5.2 (including)
FreebsdFreebsd5.2.1-release (including)5.2.1-release (including)
FreebsdFreebsd5.2.1-releng (including)5.2.1-releng (including)
FreebsdFreebsd5.3 (including)5.3 (including)
FreebsdFreebsd5.3-release (including)5.3-release (including)
FreebsdFreebsd5.3-stable (including)5.3-stable (including)
Kfreebsd-5Ubuntudapper*
Kfreebsd-5Ubuntudevel*
Kfreebsd-5Ubuntuedgy*
Kfreebsd-5Ubuntufeisty*

References