CVE-2009-1041
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
26/03/2009
Last modified:
09/04/2025
Description
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:release:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:release-p8:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:release-p9:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:releng:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:stable:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.1:pre-release:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.1:release-p1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.1:release-p2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.1:stable:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.asc
- http://www.securityfocus.com/bid/34196
- http://www.securitytracker.com/id?1021882=
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49362
- https://www.exploit-db.com/exploits/8261
- http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.asc
- http://www.securityfocus.com/bid/34196
- http://www.securitytracker.com/id?1021882=
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49362
- https://www.exploit-db.com/exploits/8261



