CVE-2005-0708: Critical severity FreeBSD FreeBSD vulnerability
The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0708?
CVE-2005-0708 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2005-0708?
To fix CVE-2005-0708, users should upgrade to a patched version of FreeBSD beyond 5.4 or implement workarounds that prevent the usage of the sendfile system call.
What does CVE-2005-0708 exploit?
CVE-2005-0708 exploits the sendfile system call by allowing remote attackers to access portions of kernel memory when a file is truncated during transmission.
Which FreeBSD versions are affected by CVE-2005-0708?
CVE-2005-0708 affects FreeBSD versions from 4.8 to 5.4, including various releases and updates within those ranges.
Can CVE-2005-0708 lead to data leakage?
Yes, CVE-2005-0708 can lead to data leakage as it may allow attackers to obtain sensitive information residing in kernel memory.