CVE-2005-1406: Medium severity FreeBSD FreeBSD vulnerability
Published May 6, 2005
·Updated
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.
Affected Software
15 affected components
FreeBSD FreeBSD=4.1
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.3
FreeBSD FreeBSD=4.4
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.6
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.9
FreeBSD FreeBSD=4.10
FreeBSD FreeBSD=4.11
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.3
FreeBSD FreeBSD=5.4
Remediation
Event History
May 6, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1406?
CVE-2005-1406 is considered a medium severity vulnerability due to the risk of sensitive memory data exposure.
2
How do I fix CVE-2005-1406?
To fix CVE-2005-1406, upgrade your FreeBSD system to a patched version that resolves this issue.
3
Which FreeBSD versions are affected by CVE-2005-1406?
CVE-2005-1406 affects FreeBSD versions 4.x from 4.1 to 4.11 and 5.x from 5.1 to 5.4.
4
What kind of data exposure does CVE-2005-1406 allow?
CVE-2005-1406 allows applications to potentially read previously used sensitive information from memory.
5
Is CVE-2005-1406 specific to FreeBSD?
Yes, CVE-2005-1406 specifically affects the FreeBSD operating system.