CVE-2014-3873: Input Validation
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3873?
CVE-2014-3873 has been rated as a moderate vulnerability due to its potential to expose sensitive kernel memory to local users.
How do I fix CVE-2014-3873?
To mitigate CVE-2014-3873, upgrade your FreeBSD system to versions 8.4-p11, 9.1-p14, 9.2-p7, or 9.3-BETA1-p1 or later.
Who is affected by CVE-2014-3873?
CVE-2014-3873 affects local users running FreeBSD versions 8.4, 9.1, 9.2, or 9.3-BETA1 prior to the specified updates.
What systems are vulnerable to CVE-2014-3873?
Systems running FreeBSD kernel versions 8.4, 9.1, 9.2, and 9.3-BETA1 before the mentioned patches are vulnerable to CVE-2014-3873.
What does CVE-2014-3873 exploit?
CVE-2014-3873 exploits an incorrect page fault kernel trace entry size within the ktrace utility to leak sensitive information.