National Cyber Awareness System
Vulnerability Summary for CVE-2014-0998
Original release date: 02/02/2015
Last revised: 02/04/2015
Source: US-CERT/NIST
Overview
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 10.1 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.
Impact
CVSS Severity (version 2.0):
Impact Subscore: 10.0
Exploitability Subscore: 3.9
CVSS Version 2 Metrics:
Access Vector: Locally exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
External Source: MISC
Name: http://www.coresecurity.com/advisories/freebsd-kernel-multiple-vulnerabilities
External Source: BUGTRAQ
Name: 20150127 [CORE-2015-0003] – FreeBSD Kernel Multiple Vulnerabilities
External Source: FULLDISC
Name: 20150127 [CORE-2015-0003] – FreeBSD Kernel Multiple Vulnerabilities
Vulnerable software and versions
+ Configuration 1
+ OR
* cpe:/o:freebsd:freebsd:10.1
Technical Details
Change History 1 change record found – show changes
Quality Assurance – 2/4/2015 12:02:06 AM | |||||||
---|---|---|---|---|---|---|---|
Action | Type | Old Value | New Value | ||||
Added | CPE Configuration |
|
|||||
Changed | Reference Type |
|
|
||||
Changed | Reference Type |
|
|
||||
Added | CVSS Vector |
|
|||||
Added | CWE |
|
|||||
Changed | Reference Type |
|
|