Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://cturt.github.io/sendmsg.html | exploit |
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:19.sendmsg.asc | vendor advisory |
http://www.securitytracker.com/id/1035906 | vdb entry |