FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
BID:20440
Info
FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
| Bugtraq ID: | 20440 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4516 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 10 2006 12:00AM |
| Updated: | Oct 13 2006 06:59PM |
| Credit: | The original discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
FreeBSD FreeBSD 6.0 -RELEASE |
| Not Vulnerable: |
FreeBSD FreeBSD 6.1 -RELEASE |
Discussion
FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
FreeBSD is prone to a local denial-of-service vulnerability because of an input-validation flaw related to the handling of integers.
An attacker may leverage this issue to cause the affected computer to crash, denying service to legitimate users.
FreeBSD version 6.0-RELEASE is vulnerable to this issue; other versions may also be affected.
FreeBSD is prone to a local denial-of-service vulnerability because of an input-validation flaw related to the handling of integers.
An attacker may leverage this issue to cause the affected computer to crash, denying service to legitimate users.
FreeBSD version 6.0-RELEASE is vulnerable to this issue; other versions may also be affected.
Exploit / POC
FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
An exploit is available.
An exploit is available.
Solution / Fix
FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate that this issue has been fixed in FreeBSD version 6.1, but Symantec has not verified this claim.
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate that this issue has been fixed in FreeBSD version 6.1, but Symantec has not verified this claim.
References
FreeBSD PTrace PT_LWPINFO Local Denial of Service Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- iDefense Security Advisory 10.10.06: FreeBSD ptrace PT_LWPINFO Denial of Service (iDefense Labs
)