积极预防 及时发现
快速响应 力保恢复
FreeBSD 内核中包含一个fstatfs()函数,用来获取文件系统的状态信息。Procfs是进程...
发布时间:2002-03-14 信息来源:管理员

CNCVE编号:CNCVE-20020070 CVE编号: 安全级别:高 漏洞中文描述: FreeBSD 内核中包含一个fstatfs()函数,用来获取文件系统的状态信息。Procfs是进程文件系统,它提供了一个指向系统进程表以及相关数据的文件系统接口。在fstatfs函数中存在一个竞争条件,可能导致本地内核崩溃,造成拒绝服务。在调用fstatfs()函数以及某文件被访问之间,该文件可以被删除,这将造成文件描述符变得无效。目前已知procfs文件系统受到此问题影响,当procfs被装载时,本地未授权用户可以造成内核崩溃。 漏洞英文描述: fstatfs() is a function that retrieves filesystem statistics in the kernel. Procfs is the process filesystem, which presents a filesystem interface to the system process table and associated data. A race condition existed where a file could be removed between calling fstatfs() and the point where the file is accessed causing the file descriptor to become invalid. This may allow unprivileged local users to cause a kernel panic. Currently only the procfs filesystem is known to be vulnerable. On vulnerable FreeBSD systems where procfs is mounted, unprivileged local users may be able to cause a kernel panic. 漏洞参考: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:09.fstatfs.asc 系统类型:其他 漏洞类型:设计错误