CVE-2008-3890: High severity freebsd kernel vulnerability
Published Sep 5, 2008
·Updated
The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.
Affected Software
3 affected components
FreeBSD FreeBSD=6.3
FreeBSD FreeBSD=7.0
AMD AMD64
Event History
Sep 5, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:08 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-3890?
CVE-2008-3890 is considered a privilege escalation vulnerability.
2
What systems are affected by CVE-2008-3890?
CVE-2008-3890 affects FreeBSD versions 6.3 and 7.0 on amd64 platforms.
3
How do I fix CVE-2008-3890?
To mitigate CVE-2008-3890, upgrade to a patched version of FreeBSD that addresses this vulnerability.
4
Can local users exploit CVE-2008-3890?
Yes, local users can exploit CVE-2008-3890 by triggering a General Protection Fault.
5
What type of vulnerability is CVE-2008-3890?
CVE-2008-3890 is classified as a kernel vulnerability related to handling General Protection Faults.