vendor:
FreeBSD
by:
kcope
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 4.11-RELEASE
Affected Version To: FreeBSD 4.11-RELEASE
Patch Exists: YES
Related CWE: CVE-2005-0448
CPE: o:freebsd:freebsd
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0013-cve-2008-5302/, https://www.rapid7.com/db/vulnerabilities/apple-osx-perl-cve-2008-5303/, https://www.rapid7.com/db/vulnerabilities/apple-osx-perl-cve-2008-5302/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-5302/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-5303/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-700-1/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-5303/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0013-cve-2008-5303/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-5302/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-5302/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-2827/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2005-881/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2005-881/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-4a99d61c-f23a-11dd-9f55-0030843d3802/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-13b0c8c8-bee0-11dd-a708-001fc66e7203/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2005-0448/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2005-0448/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2005-0448/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2005
FreeBSD master.passwd disclosure exploit
This exploit allows an attacker to gain access to the master.passwd file on an unpatched FreeBSD 4.11-RELEASE system. The exploit works by creating a socket connection and sending a file containing 64000000 'A' characters. The file is then written to a kmem file which contains the master.passwd file.
Mitigation:
Apply the patch provided in the FreeBSD-SA-05:02.sendfile.asc advisory.