FreeBSD-SA-08:08Vendor advisory
http://security.freebsd.org/advisories/FreeBSD-SA-08:08.nmount.asc CVE-2008-3531
FreeBSD 7.0/7.1 - 'vfs.usermount' Local Privilege Escalation
Record summary
CVE-2008-3531 has a selected CVSS score of 6.9; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data" in "certain error conditions."
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBFreeBSD 7.0/7.1 - 'vfs.usermount' Local Privilege EscalationExploitDB exploitby Patroklos ArgyroudisNot analyzed1 file
Repository PoCs
GitHubtest-one9/ps4-11.50.github.ioRepository PoCby test-one9Stars: 0Not analyzed2 files
References
531002vdb entry
http://www.securityfocus.com/bid/31002 1020816vdb entry
http://www.securitytracker.com/id?1020816 freebsd-vfsmount-bo(45143)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45143 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-3531