← Back

CVE-2003-1234

nvd nist
Published: Dec 31, 2003Modified: Apr 16, 2026

JSON object

Loading...
3.6
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 3.9 / Impact: 4.9
Source: NVD

Description

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

Affected (43)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
43 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 1.1.5.1
Version 2.1.0
Version 2.1.5
Version 2.1.6.1
Version 2.1.6
Version 2.1.7.1
Version 2.1.7
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2
Version 2.2 current
Version 3.1
Version 3.2
Version 3.3
Version 3.4
Version 3.5.1 release
Version 3.5
Version 4.10
Version 4.10 release
Version 4.10 release_p8
Version 4.10 releng
Version 4.11
Version 4.11 release_p3
Version 4.11 releng
Version 4.11 stable
Version 4.2
Version 4.3
Version 4.3 release
Version 4.4
Version 4.5
Version 4.5 release
Version 4.6
Version 4.6 release
Version 4.7
Version 4.7 release
Version 4.9 releng
Version 5.0

References (18)

ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:44.filedesc.asc (unsafe URL)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:44.filedesc.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.