CVE-2018-17155
Summary
| CVE | CVE-2018-17155 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-28 13:29:00 UTC |
| Updated | 2018-11-23 14:08:00 UTC |
| Description | In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userland in the getcontext and swapcontext system calls, small amounts of kernel memory may be disclosed to userland processes. Unprivileged authenticated local users may be able to access small amounts privileged kernel data. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Freebsd | Freebsd | All | All | All | All |
| Operating System | Freebsd | Freebsd | 10.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 10.4 | p13 | All | All |
| Operating System | Freebsd | Freebsd | 11.1 | p15 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p4 | All | All |
| Operating System | Freebsd | Freebsd | All | All | All | All |
| Operating System | Freebsd | Freebsd | 10.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 10.4 | p13 | All | All |
| Operating System | Freebsd | Freebsd | 11.1 | p15 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p4 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.FreeBSD.org/advisories/FreeBSD-EN-18:12.mem.asc | CONFIRM | security.FreeBSD.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.