First published: Thu Oct 12 2006(Updated: )
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used in an unsigned copyout function call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =6.0-release | |
=6.0-release |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4516 is classified as a medium severity vulnerability due to its potential for causing denial of service.
To mitigate CVE-2006-4516, upgrade to a later version of FreeBSD that has patched this vulnerability.
Local users of FreeBSD 6.0-RELEASE are affected by CVE-2006-4516.
CVE-2006-4516 can be exploited using crafted PT_LWPINFO ptrace commands that trigger memory corruption.
Exploitation of CVE-2006-4516 can lead to memory corruption and a kernel panic, resulting in denial of service.