Total vulnerabilities in the database
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
Software | From | Fixed in |
---|---|---|
freebsd / freebsd | 10.0 | 10.0.x |
freebsd / freebsd | 9.0-beta1 | 9.0-beta1.x |
freebsd / freebsd | 10.1-rc4 | 10.1-rc4.x |
freebsd / freebsd | 10.1-rc2 | 10.1-rc2.x |
freebsd / freebsd | 10.1-rc3 | 10.1-rc3.x |
freebsd / freebsd | 9.0 | 9.0.x |
freebsd / freebsd | 9.1 | 9.1.x |
freebsd / freebsd | 9.2 | 9.2.x |
freebsd / freebsd | 9.3 | 9.3.x |
freebsd / freebsd | 10.1-rc1 | 10.1-rc1.x |
freebsd / freebsd | 8.4 | 8.4.x |
freebsd / freebsd | 9.0-beta2 | 9.0-beta2.x |
freebsd / freebsd | 10.1 | 10.1.x |