Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4210

Опубликовано: 22 нояб. 2010
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a file system that uses pseudofs.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.3 (исключая)
cpe:2.3:o:freebsd:freebsd:8.0:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:p6:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00257
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-667

Связанные уязвимости

CVSS3: 7.8
debian
около 15 лет назад

The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x ...

CVSS3: 7.8
github
больше 3 лет назад

The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a file system that uses pseudofs.

EPSS

Процентиль: 49%
0.00257
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-667