vendor:
FreeBSD
by:
davidxu
7,2
CVSS
HIGH
Denial of Service
20
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 5.5-RELEASE
Affected Version To: FreeBSD 6.1-RELEASE-p10
Patch Exists: YES
Related CWE: N/A
CPE: o:freebsd:freebsd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 5.5-RELEASE, 6.0-RELEASE-p5, 6.1-RELEASE, 6.1-RELEASE-p10
2006
FreeBSD cvs commit: src/sys/posix4/p1003_1b.c
A local denial of service vulnerability exists in FreeBSD due to a lack of proper validation of user-supplied input when setting a scheduler policy. An attacker can exploit this vulnerability by running a specially crafted program that sets a scheduler policy, resulting in a denial of service condition.
Mitigation:
Upgrade to the latest version of FreeBSD.