vendor:
FreeBSD
by:
maxim, kokanin
7,2
CVSS
HIGH
Denial of Service
20
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 6.0-RELEASE-p5
Affected Version To: FreeBSD 6.1-RELEASE-p10
Patch Exists: YES
Related CWE: N/A
CPE: o:freebsd:freebsd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2006
FreeBSD ftruncate() Local Denial of Service Vulnerability
A local denial of service vulnerability exists in FreeBSD due to an incorrect handling of ftruncate() requests for non-VREG, VDIR and shared memory objects. An attacker can exploit this vulnerability by creating a FIFO file and then calling ftruncate() on it with a large size argument, resulting in a system crash.
Mitigation:
Upgrade to the latest version of FreeBSD