CVE-2014-0998: High severity freebsd kernel vulnerability
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VTWAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0998?
CVE-2014-0998 is considered a high severity vulnerability due to its potential to cause a denial of service and escalate privileges.
How do I fix CVE-2014-0998?
To fix CVE-2014-0998, ensure you upgrade to FreeBSD version 10.1 p6 or later.
Who is affected by CVE-2014-0998?
CVE-2014-0998 affects local users of FreeBSD versions 9.3 before p10 and 10.1 before p6.
What type of vulnerability is CVE-2014-0998?
CVE-2014-0998 is an integer signedness error that can lead to an array index error in the vt console driver.
Can CVE-2014-0998 be exploited remotely?
CVE-2014-0998 requires local access to the system, making it not exploitable remotely.