Vulnerability Details CVE-2020-7460
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a mailcious userspace program to modify control message headers after they were validation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.6%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 4.4
Products affected by CVE-2020-7460
-
cpe:2.3:o:freebsd:freebsd:11.3
-
cpe:2.3:o:freebsd:freebsd:11.4
-
cpe:2.3:o:freebsd:freebsd:12.1