Information Disclosure Vulnerability in FreeBSD and NetBSD's 802.11 Stack
CVE-2011-2480

7.5HIGH

Key Information:

Vendor
CVE Published:
27 November 2019

What is CVE-2011-2480?

An information disclosure vulnerability exists in the 802.11 stack utilized by FreeBSD and NetBSD operating systems. This issue arises from a signedness error in the IEEE80211_IOC_CHANINFO ioctl. If exploited by a local, unprivileged user, this vulnerability allows the user to retrieve large amounts of kernel memory, potentially exposing sensitive data. Such memory disclosures pose a significant risk to system security, enabling unauthorized access to critical information stored within the kernel.

Affected Version(s)

FreeBSD before 8.2

NetBSD

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.