First published: Fri May 02 2014(Updated: )
The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =10.0 | |
=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3001 is classified as a medium severity vulnerability due to its impact on jails and device nodes.
To fix CVE-2014-3001, upgrade to FreeBSD 10.0-p2 or later versions where the issue has been addressed.
CVE-2014-3001 can be exploited by context-dependent attackers to bypass restrictions in jailed device node processes.
CVE-2014-3001 affects FreeBSD version 10.0 before patch level p2.
CVE-2014-3001 impacts the device file system (devfs) in FreeBSD.