CVE Vulnerabilities

CVE-2004-1066

Published: Jan 10, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 4.0 (including) 4.0 (including)
Freebsd Freebsd 4.1 (including) 4.1 (including)
Freebsd Freebsd 4.1.1 (including) 4.1.1 (including)
Freebsd Freebsd 4.2 (including) 4.2 (including)
Freebsd Freebsd 4.3 (including) 4.3 (including)
Freebsd Freebsd 4.4 (including) 4.4 (including)
Freebsd Freebsd 4.5 (including) 4.5 (including)
Freebsd Freebsd 4.6 (including) 4.6 (including)
Freebsd Freebsd 4.7 (including) 4.7 (including)
Freebsd Freebsd 4.8 (including) 4.8 (including)
Freebsd Freebsd 4.8-releng (including) 4.8-releng (including)
Freebsd Freebsd 4.9 (including) 4.9 (including)
Freebsd Freebsd 4.10 (including) 4.10 (including)
Freebsd Freebsd 4.10-release (including) 4.10-release (including)
Freebsd Freebsd 4.10-releng (including) 4.10-releng (including)
Freebsd Freebsd 5.0 (including) 5.0 (including)
Freebsd Freebsd 5.1 (including) 5.1 (including)
Freebsd Freebsd 5.2 (including) 5.2 (including)
Freebsd Freebsd 5.2.1-release (including) 5.2.1-release (including)
Freebsd Freebsd 5.2.1-releng (including) 5.2.1-releng (including)
Freebsd Freebsd 5.3 (including) 5.3 (including)
Freebsd Freebsd 5.3-release (including) 5.3-release (including)
Freebsd Freebsd 5.3-stable (including) 5.3-stable (including)
Kfreebsd-5 Ubuntu dapper *
Kfreebsd-5 Ubuntu devel *
Kfreebsd-5 Ubuntu edgy *
Kfreebsd-5 Ubuntu feisty *

References