CVE-2016-1887: Buffer Overflow
Integer signedness error in the sockargs function in sys/kern/uipcsyscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1887?
CVE-2016-1887 is considered a medium severity vulnerability that can lead to denial of service or privilege escalation.
How do I fix CVE-2016-1887?
To mitigate CVE-2016-1887, update to FreeBSD versions 10.1-p34, 10.2-p17, or 10.3-p3 or later.
What types of systems are affected by CVE-2016-1887?
CVE-2016-1887 affects FreeBSD versions 10.1, 10.2, and 10.3.
What can attackers do exploiting CVE-2016-1887?
Exploiting CVE-2016-1887 allows attackers to cause a memory overwrite, leading to kernel panic or potentially gaining elevated privileges.
Who is vulnerable to CVE-2016-1887?
Local users on affected FreeBSD systems are vulnerable to CVE-2016-1887.