Vulnerability Details CVE-2014-8476
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.7%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2014-8476
-
cpe:2.3:o:freebsd:freebsd:10.0
-
cpe:2.3:o:freebsd:freebsd:10.1
-
cpe:2.3:o:freebsd:freebsd:8.4
-
cpe:2.3:o:freebsd:freebsd:9.0
-
cpe:2.3:o:freebsd:freebsd:9.1
-
cpe:2.3:o:freebsd:freebsd:9.2
-
cpe:2.3:o:freebsd:freebsd:9.3