First published: Tue Jul 26 2005(Updated: )
The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =5.0 | |
FreeBSD Kernel | =5.0-alpha | |
FreeBSD Kernel | =5.0-release_p14 | |
FreeBSD Kernel | =5.0-releng | |
FreeBSD Kernel | =5.1 | |
FreeBSD Kernel | =5.1-alpha | |
FreeBSD Kernel | =5.1-release | |
FreeBSD Kernel | =5.1-release_p5 | |
FreeBSD Kernel | =5.1-releng | |
FreeBSD Kernel | =5.2 | |
FreeBSD Kernel | =5.2.1 | |
FreeBSD Kernel | =5.2.1-release | |
FreeBSD Kernel | =5.2.1-releng | |
FreeBSD Kernel | =5.3 | |
FreeBSD Kernel | =5.3-release | |
FreeBSD Kernel | =5.3-releng | |
FreeBSD Kernel | =5.3-stable | |
FreeBSD Kernel | =5.4 | |
FreeBSD Kernel | =5.4-pre-release | |
FreeBSD Kernel | =5.4-release | |
FreeBSD Kernel | =5.4-releng |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2218 is considered a high severity vulnerability due to the potential for unauthorized access to hidden devices.
To fix CVE-2005-2218, it is recommended to upgrade to a stable version of FreeBSD that addresses this vulnerability.
CVE-2005-2218 affects FreeBSD versions 5.x including 5.0, 5.1, 5.2.1, 5.3, and 5.4.
CVE-2005-2218 enables attackers to bypass restrictions on jailed processes by accessing hidden devices.
CVE-2005-2218 is primarily a local vulnerability, since it requires local access to exploit the device file system.