CVE-2014-8476
13.11.2014, 21:32
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.Enginsight
Vendor | Product | Version |
---|---|---|
freebsd | freebsd | 8.4 |
freebsd | freebsd | 9.0 |
freebsd | freebsd | 9.0:beta1 |
freebsd | freebsd | 9.0:beta2 |
freebsd | freebsd | 9.1 |
freebsd | freebsd | 9.2 |
freebsd | freebsd | 9.3 |
freebsd | freebsd | 10.0 |
freebsd | freebsd | 10.1 |
freebsd | freebsd | 10.1:rc1 |
freebsd | freebsd | 10.1:rc2 |
freebsd | freebsd | 10.1:rc3 |
freebsd | freebsd | 10.1:rc4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References