CVE-2018-17154 Information
Feb 14, 2021
cve
Description
In FreeBSD before 11.2-STABLE(r338987) 11.2-RELEASE-p4 and 11.1-RELEASE-p15 due to insufficient memory checking in the freebsd4_getfsstat system call a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to cause a denial of service.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Reference
https://security.FreeBSD.org/advisories/FreeBSD-EN-18:10.syscall.asc
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
5.5
Share on: