Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreeBSD 整数符号错误漏洞
Vulnerability Description
FreeBSD是由Core Team团队负责的FreeBSD项目中的一套类Unix自由操作系统,是经过BSD、386BSD和4.4BSD发展而来的类Unix的一个重要分支。 FreeBSD的sys/dev/kbd/kbd.c文件中的‘genkbd_commonioctl’函数存在整数符号错误漏洞。本地攻击者可借助SETFKEY ioctl调用的‘arg’参数中的flen结构体成员中的负值利用该漏洞获取内核内存中的敏感信息,造成拒绝服务(内存覆盖和内存崩溃),或获取权限。以下版本受到影响:FreeBSD p
CVSS Information
N/A
Vulnerability Type
N/A