CVE-2019-5596
Dashboard / Vulnerabilities / CVE-2019-5596
CVE-2019-5596
Published: 12 Feb 2019Last Modified: 4 Jun 2024
Summary:
Details: In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.
References: https://security.FreeBSD.org/advisories/FreeBSD-SA-19:02.fd.asc, http://packetstormsecurity.com/files/155790/FreeBSD-fd-Privilege-Escalation.html
Affected packages
Package
Name: kfreebsd-10
Purl: pkg:deb/debian/kfreebsd-10?arch=source
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
10.3~svn300087+ds1-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
