Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2171

Опубликовано: 02 июл. 2013
Источник: nvd
CVSS2: 6.9
EPSS Средний

Описание

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass filesystem write permissions and consequently gain privileges via a crafted application that leverages read permissions, and makes mmap and ptrace system calls.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:freebsd:freebsd:9.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.1:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.1:p4:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.2417
Средний

6.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 12 лет назад

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass filesystem write permissions and consequently gain privileges via a crafted application that leverages read permissions, and makes mmap and ptrace system calls.

debian
больше 12 лет назад

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementati ...

github
больше 3 лет назад

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass filesystem write permissions and consequently gain privileges via a crafted application that leverages read permissions, and makes mmap and ptrace system calls.

EPSS

Процентиль: 96%
0.2417
Средний

6.9 Medium

CVSS2

Дефекты

CWE-264