CVE-2008-5736 describes multiple unspecified privilege escalation vulnerabilities in various versions of FreeBSD 6 and 7. These flaws stem from improperly initialized function pointers within netgraph and Bluetooth socket implementations. A local attacker could leverage these vulnerabilities to gain elevated privileges on affected systems. The vulnerability has a CVSS score of 7.2, indicating high severity with a local attack vector, low attack complexity, and complete confidentiality, integrity, and availability impacts. This means an attacker with local access could fully compromise the system. While there is no evidence of active exploitation in the wild or Metasploit modules, an exploit for Netgraph privilege escalation (EDB-16951) is available on ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:6.0:-:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:6.3:-:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:6.3:p1:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:6.3:p2:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:6.3:p3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.