Search

published date: July 5, 2005

CVE-2005-2019 : ipfw in FreeBSD 5.4,...

Description

ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to be corrupted during multiple concurrent lookups, allowing remote attackers to bypass intended access restrictions.

Product(s):

  • FreeBSD 5.4
  • FreeBSD 5.4 Patch 10
  • FreeBSD 5.4 Patch 11
  • FreeBSD 5.4 Patch 12
  • FreeBSD 5.4 Patch 13

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-2019, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-2019 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?