Vulnerability CVE-2018-6924


Published: 2018-09-12

Description:
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.6/10
7.8/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Complete
Affected software
Freebsd -> Freebsd 

 References:
http://www.securitytracker.com/id/1041646
https://security.freebsd.org/advisories/FreeBSD-SA-18:12.elf.asc

Copyright 2024, cxsecurity.com

 

Back to Top