vendor:
FreeBSD
by:
Patroklos Argyroudis
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 7.0-RELEASE
Affected Version To: FreeBSD 7.0-RELEASE
Patch Exists: YES
Related CWE: CVE-2008-3531
CPE: o:freebsd:freebsd
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2008
Privilege escalation exploit for the FreeBSD-SA-08:08.nmount (CVE-2008-3531)
This exploit is for the FreeBSD-SA-08:08.nmount (CVE-2008-3531) vulnerability. It uses a mmap() to map a page of memory, then uses nmount() to write kernelcode to the mapped page. This kernelcode sets the uid and ruid of the current process to 0, thus granting root privileges.
Mitigation:
The vulnerability can be mitigated by disabling the vfs.usermount sysctl.