7.2
CVSSv2

CVE-2014-0998

Published: 02/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 10.1

Vendor Advisories

Debian Bug report logs - #779194 kfreebsd-10: CVE-2014-0998: vt crash via ioctl Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 25 Feb 2015 11:39:01 UTC Severity: grave Tags: patch, secu ...
Debian Bug report logs - #779195 kfreebsd-10: CVE-2015-1414: DoS via IGMP packet Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 25 Feb 2015 11:39:08 UTC Severity: grave Tags: patch, sec ...

Exploits

Core Security - Corelabs Advisory corelabscoresecuritycom/ FreeBSD Kernel Multiple Vulnerabilities 1 *Advisory Information* Title: FreeBSD Kernel Multiple Vulnerabilities Advisory ID: CORE-2015-0003 Advisory URL: wwwcoresecuritycom/content/freebsd-kernel-multiple-vulnerabilities Date published: 2015-01-27 Date of last update ...
Core Security Technologies Advisory - Multiple vulnerabilities have been found in the FreeBSD kernel code that implements the vt console driver (previously known as Newcons) and the code that implements SCTP sockets These vulnerabilities could allow local unprivileged attackers to disclose kernel memory containing sensitive information, crash the ...