CVE-2010-3014: Infoleak
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large outsize value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3014?
CVE-2010-3014 is classified as a medium severity vulnerability due to its potential for unauthorized heap memory access.
How do I fix CVE-2010-3014?
To fix CVE-2010-3014, update your NetBSD or FreeBSD systems to include the latest patches that address this vulnerability.
Who is affected by CVE-2010-3014?
Users of the Coda filesystem kernel module on NetBSD and FreeBSD systems are affected by CVE-2010-3014.
What type of vulnerability is CVE-2010-3014?
CVE-2010-3014 is a buffer over-read vulnerability that allows local users to read sensitive memory.
What systems are vulnerable to CVE-2010-3014?
Both FreeBSD and NetBSD systems that are running Coda with Venus active are vulnerable to CVE-2010-3014.