ID:8948 - Exploit for Buffer overflow in FreeBSD - CVE-2019-5596

 
Main Vulnerability Database Exploits ID:8948 - Exploit for Buffer overflow in FreeBSD - CVE-2019-5596

ID:8948 - Exploit for Buffer overflow in FreeBSD - CVE-2019-5596

Published: March 29, 2023


Vulnerability identifier: #VU17378
Vulnerability risk: Low
CVE-ID: CVE-2019-5596
CWE-ID: CWE-120
Exploitation vector: Local access
Vulnerable software:
FreeBSD

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists in /dev/fd/due to the application attempts to handle the case where the receiving process does not provide a sufficiently large buffer for an incoming control message containing rights. A local attacker can cause the reference counter to wrap around and free the file structure and gain root privileges.


Remediation

Install updates from vendor's website.