CVE-2014-3001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
02/05/2014
Last modified:
12/04/2025

Description

The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*