FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 8.0 | 8.0 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.3 | 7.3 |
Freebsd | Freebsd | 7.2 | 7.2 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.2 | 7.2 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 8.1 | 8.1 |
Freebsd | Freebsd | 7.1 | 7.1 |
Freebsd | Freebsd | 7.2 | 7.2 |