Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2218

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-2005-2218
Last Modified 05 Sep 2008 04:51:11
Published 26 Jul 2005 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2005-2218

Summary

The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.

Vulnerable Systems

Operating System

  • Freebsd 5.0

  • Freebsd 5.1

  • Freebsd 5.2

  • Freebsd 5.2.1

  • Freebsd 5.3

  • Freebsd 5.4


References

FREEBSD - FreeBSD-SA-05:17

XF - freebsd-devfs-gain-privileges(21451)

BID - 14334

OSVDB - 18123

SECTRACK - 1014536

SECUNIA - 16145


Last Updated: 27 May 2016 10:40:26