The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail.
Attacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by "pstat -t" may be leaked.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc | Vendor Advisory |
https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240510-0003/ | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20240510-0003/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
04 Jun 2025, 21:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.netapp.com/advisory/ntap-20240510-0003/ - Third Party Advisory | |
References | () https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Freebsd
Freebsd freebsd |
|
CPE | cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:* |
10 Jun 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Feb 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-15 05:15
Updated : 2025-06-04 21:55
NVD link : CVE-2024-25941
Mitre link : CVE-2024-25941
JSON object : View
Products Affected
freebsd
- freebsd
CWE