Vulnerabilities > CVE-2019-5602 - Incorrect Authorization vulnerability in Freebsd 11.2/11.3/12.0

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
freebsd
CWE-863
critical
nessus

Summary

In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite kernel memory when media is present thereby allowing a malicious user in the operator group to gain root privileges.

Vulnerable Configurations

Part Description Count
OS
Freebsd
18

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_14A3B376B30A11E9A87FA4BADB2F4699.NASL
    descriptionTo implement one particular ioctl, the Linux emulation code used a special interface present in the cd(4) driver which allows it to copy subchannel information directly to a kernel address. This interface was erroneously made accessible to userland, allowing users with read access to a cd(4) device to arbitrarily overwrite kernel memory when some media is present in the device. Impact : A user in the operator group can make use of this interface to gain root privileges on a system with a cd(4) device when some media is present in the device.
    last seen2020-06-01
    modified2020-06-02
    plugin id127540
    published2019-08-12
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/127540
    titleFreeBSD : FreeBSD -- Privilege escalation in cd(4) driver (14a3b376-b30a-11e9-a87f-a4badb2f4699)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_SA-19-11_CD_IOCTL.NASL
    descriptionThe version of the FreeBSD kernel running on the remote host is 11.x prior to 11.2-RELEASE-p11 or 12.x prior to 12.0-RELEASE-p7. It is, therefore, affected by a privilege escalation vulnerability in the cd(4) driver. A local attacker with read access to a cd(4) device can exploit this to gain root privileges on the system.
    last seen2020-06-01
    modified2020-06-02
    plugin id126647
    published2019-07-15
    reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126647
    titleFreeBSD 11.x < 11.2-RELEASE-p12 / 12.x < 12.0-RELEASE-p7 Privilege escalation in cd(4) driver