Security Advisory

CVE-2009-1935

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-06-18 18:00:00
Last updated 2024-08-07 05:27:54
Assigner freebsd
CVSS score not scored
State PUBLISHED

Description

Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.