CVE-2003-1234: Integer Overflow
Integer overflow in the fcount counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement fcount through a call to fdrop.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1234?
CVE-2003-1234 is classified as a moderate vulnerability that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2003-1234?
To fix CVE-2003-1234, users should upgrade to a patched version of FreeBSD that addresses the integer overflow issue.
Which FreeBSD versions are affected by CVE-2003-1234?
CVE-2003-1234 affects multiple FreeBSD versions, including 2.1, 2.2, 4.2 through 5.0.
What type of attack can CVE-2003-1234 facilitate?
CVE-2003-1234 can facilitate a denial of service attack as well as potentially allow arbitrary code execution.
Who can exploit CVE-2003-1234?
CVE-2003-1234 can be exploited by local users who have access to the system running the affected FreeBSD versions.