vendor:
FreeBSD
by:
babcia padlina
7.2
CVSS
HIGH
Race Condition
362
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 6.4 and below
Affected Version To: FreeBSD 6.4 and below
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Multiprocessor systems
2009
FreeBSD 6.4 and below are vulnerable to race condition between pipeclose() and knlist_cleardel() resulting in NULL pointer dereference
FreeBSD 6.4 and below are vulnerable to race condition between pipeclose() and knlist_cleardel() resulting in NULL pointer dereference. The exploit code exploits this vulnerability to run code in kernel mode, giving root shell and escaping from jail. The exploit works only on multiprocessor systems.
Mitigation:
Upgrade to FreeBSD 6.4 or later version