CVE-2005-1400: Medium severity FreeBSD FreeBSD vulnerability
Published May 6, 2005
·Updated
The i386getldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.
Affected Software
9 affected components
FreeBSD FreeBSD=5.4
FreeBSD FreeBSD=5.3
FreeBSD FreeBSD=4.11
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.10
FreeBSD FreeBSD=4.9
Remediation
Event History
May 6, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1400?
CVE-2005-1400 is considered a moderate severity vulnerability due to possible local privilege escalation.
2
How do I fix CVE-2005-1400?
To fix CVE-2005-1400, upgrade to a patched version of FreeBSD that addresses this vulnerability.
3
What versions of FreeBSD are affected by CVE-2005-1400?
CVE-2005-1400 affects FreeBSD versions 4.7 to 4.11 and 5.1 to 5.4.
4
What kind of access does CVE-2005-1400 allow to local users?
CVE-2005-1400 allows local users to access sensitive kernel memory by exploiting the i386_get_ldt system call.
5
Is CVE-2005-1400 a remote or local vulnerability?
CVE-2005-1400 is a local vulnerability, meaning it requires local access to the affected FreeBSD system to exploit.