In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory.
References
Link | Resource |
---|---|
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:06.if_ixl_ioctl.asc | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-04-28 20:15
Updated : 2024-02-28 17:47
NVD link : CVE-2019-15877
Mitre link : CVE-2019-15877
CVE.ORG link : CVE-2019-15877
JSON object : View
Products Affected
freebsd
- freebsd
CWE
CWE-862
Missing Authorization