PoC Index

CVE-2014-0998

HIGH 7.2EPSS 0.9%

Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.92% chance of exploitation in the next 30 days, 58th percentile
Published
2015-02-02
Updated
2024-08-06

ExploitDB entries (1)

References

Related