CVE-2013-3077: Integer Overflow
Multiple integer overflows in the IPMSFILTER and IPV6MSFILTER features in (1) sys/netinet/inmcast.c and (2) sys/netinet6/in6mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass intended restrictions on kernel-memory read and write operations, and consequently gain privileges, via vectors involving a large number of source-filter entries.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3077?
CVE-2013-3077 has a high severity rating due to the potential for local users to bypass kernel memory access restrictions.
How do I fix CVE-2013-3077?
To fix CVE-2013-3077, upgrade your FreeBSD system to a patched version beyond 9.2-PRERELEASE.
Which versions of FreeBSD are affected by CVE-2013-3077?
CVE-2013-3077 affects FreeBSD versions 8.3 up to 9.2-PRERELEASE.
What are the potential impacts of CVE-2013-3077?
The impacts of CVE-2013-3077 may include unauthorized access to kernel memory which can lead to data breaches.
Can CVE-2013-3077 be exploited remotely?
No, CVE-2013-3077 is a local vulnerability that requires authenticated local access to exploit.