vendor:
FreeBSD
by:
Hunger
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 9.0
Affected Version To: FreeBSD 9.1
Patch Exists: YES
Related CWE: N/A
CPE: o:freebsd:freebsd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 9.0 and 9.1
2012
FreeBSD 9.{0,1} mmap/ptrace exploit
This exploit is used to gain root privileges on FreeBSD 9.0 and 9.1 systems. It uses the mmap and ptrace system calls to copy the contents of the exploit binary into the timedc binary, which is then executed with root privileges.
Mitigation:
Ensure that all systems are running the latest version of FreeBSD and that all security patches are applied.