CVE-2019-5603

EUVD-2019-15178
In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
freebsdfreebsd
11.0
freebsdfreebsd
11.2
freebsdfreebsd
11.2:p10
freebsdfreebsd
11.2:p11
freebsdfreebsd
11.2:p2
freebsdfreebsd
11.2:p3
freebsdfreebsd
11.2:p4
freebsdfreebsd
11.2:p5
freebsdfreebsd
11.2:p6
freebsdfreebsd
11.2:p7
freebsdfreebsd
11.2:p8
freebsdfreebsd
11.2:p9
freebsdfreebsd
11.2:rc3
freebsdfreebsd
11.3
freebsdfreebsd
12.0
freebsdfreebsd
12.0:p1
freebsdfreebsd
12.0:p2
freebsdfreebsd
12.0:p3
freebsdfreebsd
12.0:p4
freebsdfreebsd
12.0:p5
freebsdfreebsd
12.0:p6
freebsdfreebsd
12.0:p7
𝑥
= Vulnerable software versions