The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/67812 | vdb entry |
http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A12.ktrace.asc | patch vendor advisory |
http://www.securitytracker.com/id/1030325 | vdb entry |
http://secunia.com/advisories/58627 | third party advisory |