The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.
2005-05-06T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | freebsd | freebsd | 4.1 | Yes |
| Operating System | freebsd | freebsd | 4.2 | Yes |
| Operating System | freebsd | freebsd | 4.3 | Yes |
| Operating System | freebsd | freebsd | 4.4 | Yes |
| Operating System | freebsd | freebsd | 4.5 | Yes |
| Operating System | freebsd | freebsd | 4.6 | Yes |
| Operating System | freebsd | freebsd | 4.7 | Yes |
| Operating System | freebsd | freebsd | 4.8 | Yes |
| Operating System | freebsd | freebsd | 4.9 | Yes |
| Operating System | freebsd | freebsd | 4.10 | Yes |
| Operating System | freebsd | freebsd | 4.11 | Yes |
| Operating System | freebsd | freebsd | 5.1 | Yes |
| Operating System | freebsd | freebsd | 5.2 | Yes |
| Operating System | freebsd | freebsd | 5.3 | Yes |
| Operating System | freebsd | freebsd | 5.4 | Yes |