FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0114

This CVE name corresponds to:

Entered Topic
2004-04-07 shmat reference counting bug

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type CVE Entry
Name CVE-2004-0114

Description

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.

References

Source Reference
BUGTRAQ 20040205 [PINE-CERT-20040201] reference count overflow in shmat()
MISC http://www.pine.nl/press/pine-cert-20040201.txt
FREEBSD FreeBSD-SA-04:02
NETBSD NetBSD-SA2004-004
CONFIRM http://www.openbsd.org/errata33.html#sysvshm
BID 9586
XF bsd-shmat-gain-privileges(15061)
OSVDB 3836