Vulnerabilities > CVE-2001-1185 - Unspecified vulnerability in Freebsd 4.4

047910
CVSS 6.2 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
high complexity
freebsd
exploit available

Summary

Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.

Vulnerable Configurations

Part Description Count
OS
Freebsd
1

Exploit-Db

descriptionFreeBSD 4.4 AIO Library Cross Process Memory Write Vulnerability. CVE-2001-1185. Local exploit for freebsd platform
idEDB-ID:21176
last seen2016-02-02
modified2001-12-10
published2001-12-10
reporterDavid Rufino
sourcehttps://www.exploit-db.com/download/21176/
titleFreeBSD 4.4 AIO Library Cross Process Memory Write Vulnerability