CVE Database
/

CVE-2024-6760

Back to search

CVE-2024-6760

Published: Aug 11, 2024

Modified: Oct 29, 2024

PUBLISHED

Description

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

VendorProductVersions

FreeBSD

FreeBSD

affected
14.1-RELEASE - < p3
affected
14.0-RELEASE - < p9
affected
13.3-RELEASE - < p5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now