Summary
The remote host is missing an update to the system as announced in the referenced advisory FreeBSD-SA-09:06.ktimer.asc
Solution
Upgrade your system to the appropriate stable release or security branch dated after the correction date
https://secure1.securityspace.com/smysecure/catid.html?in=FreeBSD-SA-09:06.ktimer.asc
Insight
In FreeBSD 7.0, support was introduced for per-process timers as defined in the POSIX realtime extensions. This allows a process to have a limited number of timers running at once, with various actions taken when each timer reaches zero.
An integer which specifies which timer a process wishes to operate upon is not properly bounds-checked.
Severity
Classification
-
CVE CVE-2009-1041 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities