The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.
References
Configurations
Information
Published : 2014-05-02 07:55
Updated : 2014-05-05 07:54
NVD link : CVE-2014-3001
Mitre link : CVE-2014-3001
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
freebsd
- freebsd