procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.
Software | From | Fixed in |
---|---|---|
freebsd / freebsd | 3.5.1 | 3.5.1.x |
freebsd / freebsd | 4.1 | 4.1.x |
freebsd / freebsd | 4.2 | 4.2.x |
freebsd / freebsd | 4.1.1 | 4.1.1.x |