4.9
CVSSv2

CVE-2009-1436

Published: 27/04/2009 Updated: 28/11/2016
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 7.2

freebsd freebsd 7.1

freebsd freebsd 7.0

freebsd freebsd 6.3

freebsd freebsd 6.4

Exploits

source: wwwsecurityfocuscom/bid/34666/info FreeBSD is prone to a local information-disclosure vulnerability Local attackers can exploit this issue to obtain sensitive information that may lead to further attacks #include <sys/typesh> #include <dbh> #include <errh> #include <fcntlh> #include <limitsh&gt ...

Recent Articles

Juniper's bug hunters fire out eight patches
The Register • Richard Chirgwin • 14 Jul 2016

Junos OS has been put through the wringer since that nasty backdoor scandal

Juniper has fired off fixes for eight security vulnerabilities. The company has been running Junos OS through the security mill since late last year, when its now-notorious backdoor hit the headlines. Junos OS systems running either generic routing encapsulation (GRE) or IP-in-IP (IPIP) tunnels are vulnerable to a kernel crash triggered by a crafted ICMP packet. The resulting denial of service attack, CVE-2016-1277, is rated high, and present in a bunch of Junos OS revisions – three in the ver...