CVE-2014-3001 Information

Description

The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.

Reference

http://www.freebsd.org/security/advisories/FreeBSD-SA-14:07.devfs.asc http://www.securityfocus.com/bid/67158 http://www.securitytracker.com/id/1030171

Share on: