CVE-2014-8476 describes an information disclosure vulnerability in FreeBSD versions 8.4 through 10.1-RC4. The flaw lies in the setlogin function, which fails to properly initialize a buffer, allowing local users to retrieve sensitive kernel memory data via the getlogin function. This vulnerability has a low severity CVSS score of 2.1, indicating a low attack complexity and requiring local access to achieve a partial confidentiality impact. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.4CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:8.4:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:9.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:9.0:beta1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:9.0:beta2:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:9.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.