Back to search
CVE-2024-6760
Published: Aug 11, 2024
Modified: Oct 29, 2024
PUBLISHED
Description
A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.
| Vendor | Product | Versions |
|---|---|---|
FreeBSD | FreeBSD | affected 14.1-RELEASE - < p3affected 14.0-RELEASE - < p9affected 13.3-RELEASE - < p5 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now