Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FreeBSD AIO Library Cross Process Memory Write Vulnerability

Solution:
This vulnerability only exists if VFS_AIO is enabled in the FreeBSD kernel. This is not enabled by default.

David Rufino <dr@soniq.net> has provided a patch to limit AIO use to the root user, which is available at:

http://elysium.soniq.net/dr/tao/patch-01








 

Privacy Statement
Copyright 2009, SecurityFocus