FreeBSD 7.1 up to and including 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
freebsd freebsd 7.1 |
||
freebsd freebsd 7.2 |
||
freebsd freebsd 7.3 |
||
freebsd freebsd 8.0 |
||
freebsd freebsd 8.1 |