CVE-2019-5603

In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
freebsdCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
freebsdfreebsd
11.0
freebsdfreebsd
11.2
freebsdfreebsd
11.2:p10
freebsdfreebsd
11.2:p11
freebsdfreebsd
11.2:p2
freebsdfreebsd
11.2:p3
freebsdfreebsd
11.2:p4
freebsdfreebsd
11.2:p5
freebsdfreebsd
11.2:p6
freebsdfreebsd
11.2:p7
freebsdfreebsd
11.2:p8
freebsdfreebsd
11.2:p9
freebsdfreebsd
11.2:rc3
freebsdfreebsd
11.3
freebsdfreebsd
12.0
freebsdfreebsd
12.0:p1
freebsdfreebsd
12.0:p2
freebsdfreebsd
12.0:p3
freebsdfreebsd
12.0:p4
freebsdfreebsd
12.0:p5
freebsdfreebsd
12.0:p6
freebsdfreebsd
12.0:p7
𝑥
= Vulnerable software versions