FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
BID:43060
Info
FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
| Bugtraq ID: | 43060 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 08 2010 12:00AM |
| Updated: | Oct 04 2010 07:20PM |
| Credit: | Przemyslaw Frasunek |
| Vulnerable: |
FreeBSD FreeBSD 8.0-RELEASE FreeBSD FreeBSD 7.2-RELEASE-p4 FreeBSD FreeBSD 7.2-RELEASE-p1 FreeBSD FreeBSD 7.1-RELEASE-p6 FreeBSD FreeBSD 7.1-RELEASE-p5 FreeBSD FreeBSD 7.1-RELEASE-p4 FreeBSD FreeBSD 7.1 -RELEASE-p2 FreeBSD FreeBSD 7.1 -RELEASE-p1 FreeBSD FreeBSD 7.0-RELEASE |
| Not Vulnerable: |
FreeBSD FreeBSD 8.1-RELEASE FreeBSD FreeBSD 7.3-RELEASE-p1 |
Discussion
FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
FreeBSD is prone to a local privilege-escalation vulnerability due to a NULL-pointer dereference condition that occurs in the 'pseudofs' filesystem.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
FreeBSD is prone to a local privilege-escalation vulnerability due to a NULL-pointer dereference condition that occurs in the 'pseudofs' filesystem.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
Exploit / POC
FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for details.
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for details.
References
FreeBSD 'pseudofs' NULL Pointer Dereference Local Privilege Escalation Vulnerability
References:
References:
- FreeBSD 7.0 - 7.2 pseudofs null pointer dereference (Przemyslaw Frasunek)
- FreeBSD Homepage (FreeBSD)