Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FreeBSD System Call Signed Integer Buffer Overflow Vulnerability

A vulnerability has been reported for the FreeBSD system. Reportedly, a few system calls are vulnerable to signed integer buffer overflow conditions.

The vulnerability is the result of system calls assuming that some arguments were given as positive integers while, in actuality, the arguments were handled as signed integers. If a negative value was supplied for the argument, the boundary checking code would fail.







 

Privacy Statement
Copyright 2008, SecurityFocus