Vulnerability Description
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 7.0 |
Related Weaknesses (CWE)
References
- http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.ascExploit
- http://www.securityfocus.com/bid/34196
- http://www.securitytracker.com/id?1021882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49362
- https://www.exploit-db.com/exploits/8261
- http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.ascExploit
- http://www.securityfocus.com/bid/34196
- http://www.securitytracker.com/id?1021882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49362
- https://www.exploit-db.com/exploits/8261
FAQ
What is CVE-2009-1041?
CVE-2009-1041 is a vulnerability with a CVSS score of 7.2 (HIGH). The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.
How severe is CVE-2009-1041?
CVE-2009-1041 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1041?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.