CVE-2005-1126: Low severity FreeBSD FreeBSD vulnerability
Published Apr 15, 2005
·Updated
The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.
Affected Software
61 affected components
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=4.0-alpha
FreeBSD FreeBSD=4.0-releng
FreeBSD FreeBSD=4.1
FreeBSD FreeBSD=4.1.1
FreeBSD FreeBSD=4.1.1-release
FreeBSD FreeBSD=4.1.1-stable
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.2-stable
FreeBSD FreeBSD=4.3
FreeBSD FreeBSD=4.3-release
FreeBSD FreeBSD=4.3-release_p38
FreeBSD FreeBSD=4.3-releng
FreeBSD FreeBSD=4.3-stable
FreeBSD FreeBSD=4.4
FreeBSD FreeBSD=4.4-release_p42
FreeBSD FreeBSD=4.4-releng
FreeBSD FreeBSD=4.4-stable
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.5-release
FreeBSD FreeBSD=4.5-release_p32
FreeBSD FreeBSD=4.5-releng
FreeBSD FreeBSD=4.5-stable
FreeBSD FreeBSD=4.6
FreeBSD FreeBSD=4.6-release
FreeBSD FreeBSD=4.6-release_p20
FreeBSD FreeBSD=4.6-releng
FreeBSD FreeBSD=4.6-stable
FreeBSD FreeBSD=4.6.2
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=4.7-release
FreeBSD FreeBSD=4.7-release_p17
FreeBSD FreeBSD=4.7-releng
FreeBSD FreeBSD=4.7-stable
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.8-pre-release
FreeBSD FreeBSD=4.8-release_p6
FreeBSD FreeBSD=4.8-releng
FreeBSD FreeBSD=4.9
FreeBSD FreeBSD=4.9-pre-release
FreeBSD FreeBSD=4.9-releng
FreeBSD FreeBSD=4.10
FreeBSD FreeBSD=4.10-release
FreeBSD FreeBSD=4.10-releng
FreeBSD FreeBSD=4.11-stable
FreeBSD FreeBSD=5.0
FreeBSD FreeBSD=5.0-alpha
FreeBSD FreeBSD=5.0-release_p14
FreeBSD FreeBSD=5.0-releng
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.1-alpha
FreeBSD FreeBSD=5.1-release
FreeBSD FreeBSD=5.1-release_p5
FreeBSD FreeBSD=5.1-releng
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.2.1-release
FreeBSD FreeBSD=5.2.1-releng
FreeBSD FreeBSD=5.3
FreeBSD FreeBSD=5.3-release
FreeBSD FreeBSD=5.3-releng
FreeBSD FreeBSD=5.3-stable
Remediation
Patch Available
Patch Available
Event History
Apr 15, 2005
CVE Published
04:00 AM
Apr 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1126?
The severity of CVE-2005-1126 is considered medium due to potential information disclosure vulnerabilities.
2
How do I fix CVE-2005-1126?
To fix CVE-2005-1126, upgrade to a patched version of FreeBSD that addresses this vulnerability.
3
Who is affected by CVE-2005-1126?
CVE-2005-1126 affects local users on FreeBSD versions 4.x and 5.x up to specified release versions.
4
What does CVE-2005-1126 allow attackers to do?
CVE-2005-1126 allows local users to obtain portions of sensitive kernel memory due to improper buffer clearing.
5
Is there a workaround for CVE-2005-1126?
There is no official workaround for CVE-2005-1126, and the recommended action is to apply the software updates.