CVE-2001-1166: Medium severity FreeBSD FreeBSD vulnerability
Published Aug 21, 2001
·Updated
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
Affected Software
4 affected components
FreeBSD FreeBSD=4.1
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=4.3
Remediation
Patch Available
Patch Available
Event History
Aug 21, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1166?
CVE-2001-1166 is considered a high severity vulnerability due to its potential to expose sensitive kernel memory.
2
How do I fix CVE-2001-1166?
To fix CVE-2001-1166, upgrade to a later version of FreeBSD that properly restricts access to kernel memory.
3
What software versions are affected by CVE-2001-1166?
CVE-2001-1166 affects FreeBSD versions 4.0, 4.1, 4.2, and 4.3.
4
Who is vulnerable to CVE-2001-1166?
Any user process on FreeBSD systems with debugging rights can exploit CVE-2001-1166 to read restricted kernel memory.
5
What impact does CVE-2001-1166 have on FreeBSD systems?
CVE-2001-1166 can lead to unauthorized access to sensitive information, compromising the security of FreeBSD systems.