First published: Thu Jun 03 2004(Updated: )
Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to files from being committed to disk.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =4.0-releng | |
FreeBSD Kernel | =4.8 | |
FreeBSD Kernel | =4.8-pre-release | |
FreeBSD Kernel | =4.8-release_p6 | |
FreeBSD Kernel | =4.8-releng | |
FreeBSD Kernel | =4.9 | |
FreeBSD Kernel | =4.9-pre-release | |
FreeBSD Kernel | =4.9-releng | |
FreeBSD Kernel | =4.10 | |
FreeBSD Kernel | =4.10-release | |
FreeBSD Kernel | =4.10-releng | |
FreeBSD Kernel | =5.2 | |
FreeBSD Kernel | =5.2.1-release | |
FreeBSD Kernel | =5.2.1-releng |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0435 has a moderate severity rating due to cache consistency issues that allow local users to prevent changes from being committed to disk.
To mitigate CVE-2004-0435, it is recommended to upgrade FreeBSD to a version later than 5.2.1 or 4.10.
CVE-2004-0435 affects FreeBSD versions 5.2.1 and earlier, and 4.10 and earlier.
No, CVE-2004-0435 can only be exploited by local users on the affected FreeBSD systems.
The potential impact of CVE-2004-0435 includes the inability to commit file changes to disk, leading to data loss and inconsistencies.