Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-1935


Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.


Published

2009-06-18T18:30:00.407

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.9 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System freebsd freebsd 6.3 Yes
Operating System freebsd freebsd 6.3 Yes
Operating System freebsd freebsd 6.3_releng Yes
Operating System freebsd freebsd 6.4 Yes
Operating System freebsd freebsd 6.4 Yes
Operating System freebsd freebsd 6.4 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.1 Yes
Operating System freebsd freebsd 7.2 Yes
Operating System freebsd freebsd 7.2 Yes

References