Information Disclosure Vulnerability in FreeBSD and NetBSD's 802.11 Stack
CVE-2011-2480
7.5HIGH
What is CVE-2011-2480?
An information disclosure vulnerability exists in the 802.11 stack utilized by FreeBSD and NetBSD operating systems. This issue arises from a signedness error in the IEEE80211_IOC_CHANINFO ioctl. If exploited by a local, unprivileged user, this vulnerability allows the user to retrieve large amounts of kernel memory, potentially exposing sensitive data. Such memory disclosures pose a significant risk to system security, enabling unauthorized access to critical information stored within the kernel.
Affected Version(s)
FreeBSD before 8.2
NetBSD
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved