Vulnerabilities > CVE-2014-0998 - Numeric Errors vulnerability in Freebsd 10.1

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
freebsd
CWE-189
exploit available

Summary

Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.

Vulnerable Configurations

Part Description Count
OS
Freebsd
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionFreeBSD Kernel - Multiple Vulnerabilities. CVE-2014-0998,CVE-2014-8612. Dos exploit for freebsd platform
idEDB-ID:35938
last seen2016-02-04
modified2015-01-29
published2015-01-29
reporterCore Security
sourcehttps://www.exploit-db.com/download/35938/
titleFreeBSD Kernel - Multiple Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/130124/CORE-2015-0003.txt
idPACKETSTORM:130124
last seen2016-12-05
published2015-01-28
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/130124/FreeBSD-Kernel-Crash-Code-Execution-Disclosure.html
titleFreeBSD Kernel Crash / Code Execution / Disclosure