Information Disclosure Vulnerability in FreeBSD and NetBSD's 802.11 Stack
CVE-2011-2480
7.5HIGH
What is CVE-2011-2480?
An information disclosure vulnerability exists in the 802.11 stack utilized by FreeBSD and NetBSD operating systems. This issue arises from a signedness error in the IEEE80211_IOC_CHANINFO ioctl. If exploited by a local, unprivileged user, this vulnerability allows the user to retrieve large amounts of kernel memory, potentially exposing sensitive data. Such memory disclosures pose a significant risk to system security, enabling unauthorized access to critical information stored within the kernel.
Affected Version(s)
FreeBSD before 8.2
NetBSD