FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-22 18:21:47 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
a5cf3ecd-38db-11e8-8b7f-a4badb2f469bFreeBSD -- vt console memory disclosure

Problem Description:

Insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Characters that reference this data can be displayed on the screen, effectively disclosing kernel memory.

Impact:

Unprivileged users may be able to access privileged kernel data.

Such memory might contain sensitive information, such as portions of the file cache or terminal buffers. This information might be directly useful, or it might be leveraged to obtain elevated privileges in some way; for example, a terminal buffer might include a user-entered password.


Discovery 2018-04-04
Entry 2018-04-05
FreeBSD-kernel
ge 11.1 lt 11.1_9

ge 10.4 lt 10.4_8

ge 10.3 lt 10.3_29

CVE-2018-6917
SA-18:04.vt