The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2005/2256 | vdb entry |
http://secunia.com/advisories/14959 | third party advisory patch vendor advisory |
http://secunia.com/advisories/17368 | third party advisory |
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:04.ifconf.asc | patch vendor advisory |
http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html | vendor advisory |
http://www.securityfocus.com/bid/15252 | vdb entry |
http://www.osvdb.org/15514 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20114 | vdb entry |