CVE-2002-1667 describes a denial-of-service vulnerability in the virtual memory management system of FreeBSD 4.5-RELEASE and earlier. A local attacker can crash the system by manipulating memory maps, specifically by calling msync on an unaccessed memory map created with MAP_ANON and MAP_NOSYNC flags. This vulnerability has a low severity CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of partial availability loss. There is no known active exploitation, publicly available exploit code in Metasploit or ExploitDB, and it is not listed on the CISA KEV catalog, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.5:release:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:4.5:stable:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.