FreeBSD ATA Device Local Denial of Service Vulnerability
BID:35645
Info
FreeBSD ATA Device Local Denial of Service Vulnerability
| Bugtraq ID: | 35645 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2649 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 13 2009 12:00AM |
| Updated: | Aug 21 2009 03:54PM |
| Credit: | Shaun Colley |
| Vulnerable: |
FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD -current |
| Not Vulnerable: | |
Discussion
FreeBSD ATA Device Local Denial of Service Vulnerability
FreeBSD is prone to a local denial-of-service vulnerability when the kernel handles a specially crafted IOCTL request to an ATA device.
Exploiting this issue allows attackers with local, interactive access to affected computers to trigger kernel panics, which will deny further service to legitimate users.
FreeBSD is prone to a local denial-of-service vulnerability when the kernel handles a specially crafted IOCTL request to an ATA device.
Exploiting this issue allows attackers with local, interactive access to affected computers to trigger kernel panics, which will deny further service to legitimate users.
Exploit / POC
FreeBSD ATA Device Local Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
FreeBSD ATA Device Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].