packetstormsecurity.com
http://packetstormsecurity.com/files/155790/FreeBSD-fd-Privilege-Escalation.html CVE-2019-5596
HIGH
FreeBSD 12.0 - 'fd' Local Privilege Escalation
Record summary
CVE-2019-5596 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits and 1 repository PoC.
Description
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FreeBSDBrowse FreeBSD / FreeBSD | CVE List | FreeBSD 12.0 before 12.0-RELEASE-p3 | affected |
Proofs of concept
3Catalogued exploits
ExploitDBFreeBSD 12.0 - 'fd' Local Privilege EscalationExploitDB exploitby gr4yf0xNot analyzed1 file
ExploitDBFreeBSD-SA-19:02.fd - Privilege EscalationExploitDB exploitby Karsten KönigNot analyzed1 file
Repository PoCs
GitHubraymontag/CVE-2019-5596Repository PoCby raymontagStars: 1Not analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-5596 FreeBSD-SA-19:02Vendor advisory
https://security.freebsd.org/advisories/FreeBSD-SA-19:02.fd.asc