CVE-2009-1436

The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.3:release_p10:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:release_p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.4:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:release-p12:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:release-p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.2:pre-release:*:*:*:*:*:*

History

21 Nov 2024, 01:02

Type Values Removed Values Added
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10756 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10756 -
References () http://osvdb.org/53918 - () http://osvdb.org/53918 -
References () http://secunia.com/advisories/34810 - Vendor Advisory () http://secunia.com/advisories/34810 - Vendor Advisory
References () http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc - Vendor Advisory () http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc - Vendor Advisory
References () http://www.securityfocus.com/bid/34666 - Exploit, Patch () http://www.securityfocus.com/bid/34666 - Exploit, Patch
References () http://www.securitytracker.com/id?1022113 - () http://www.securitytracker.com/id?1022113 -

Information

Published : 2009-04-27 18:00

Updated : 2024-11-21 01:02


NVD link : CVE-2009-1436

Mitre link : CVE-2009-1436

CVE.ORG link : CVE-2009-1436


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-20

Improper Input Validation