CVE-2004-0919: Medium severity FreeBSD FreeBSD vulnerability
Published Dec 31, 2004
·Updated
The syscons CONSSCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.
Affected Software
12 affected components
FreeBSD FreeBSD=5.1-releng
FreeBSD FreeBSD=5.1-release_p5
FreeBSD FreeBSD=5.2.1-releng
FreeBSD FreeBSD=5.0-release_p14
FreeBSD FreeBSD=5.1-release
FreeBSD FreeBSD=5.0-releng
FreeBSD FreeBSD=5.1-alpha
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.0-alpha
FreeBSD FreeBSD=5.2.1-release
FreeBSD FreeBSD=5.0
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0919?
CVE-2004-0919 has been classified as a medium severity vulnerability.
2
How does CVE-2004-0919 affect FreeBSD systems?
CVE-2004-0919 allows local users to read arbitrary kernel memory through manipulation of the syscons CONS_SCRSHOT ioctl.
3
How do I fix CVE-2004-0919?
To fix CVE-2004-0919, you should upgrade your FreeBSD systems to a patched version that resolves this vulnerability.
4
Which versions of FreeBSD are affected by CVE-2004-0919?
CVE-2004-0919 affects FreeBSD 5.0 to 5.2.1, including various specific alpha and release versions.
5
Is CVE-2004-0919 a remote or local vulnerability?
CVE-2004-0919 is a local vulnerability, meaning it can only be exploited by users with local access to the system.