FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1787 | vdb entry patch vendor advisory |
http://security.freebsd.org/advisories/FreeBSD-SA-10:07.mbuf.asc | patch vendor advisory |
http://www.securitytracker.com/id?1024182 | vdb entry patch |
http://secunia.com/advisories/40567 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/41577 | vdb entry |