CVE-2002-1125 describes a vulnerability in FreeBSD port programs utilizing libkvm, specifically affecting versions 4.6.2-RELEASE and earlier, including asmon, ascpu, bubblemon, wmmon, and wmnet2. These programs fail to close file descriptors for /dev/mem and /dev/kmem, allowing local users to read sensitive kernel memory. With a CVSS score of 2.1, this vulnerability is considered low severity, requiring local access with low attack complexity, and primarily impacting confidentiality without affecting integrity or availability. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, exploit code is publicly available on ExploitDB for several affected applications, though there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.2:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.4:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.5:*:*:*:*:*:*:* | ||
4.6CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.