kb.juniper.netConfirmation
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10756 CVE-2009-1436
FreeBSD 7.1 - libc Berkley DB Interface Uninitialized Memory Local Information Disclosure
Record summary
CVE-2009-1436 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.
Description
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFreeBSD 7.1 - libc Berkley DB Interface Uninitialized Memory Local Information DisclosureExploitDB exploitby Jaakko HeinonenNot analyzed1 file
References
753918vdb entry
http://osvdb.org/53918 34810Third-party advisory
http://secunia.com/advisories/34810 FreeBSD-SA-09:07Vendor advisory
http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc 34666vdb entry
http://www.securityfocus.com/bid/34666 1022113vdb entry
http://www.securitytracker.com/id?1022113 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1436