CVE-2014-8476

low
Published 2014-11-13 · Modified 2026-05-06
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.debian.org/security/2014/dsa-3070

OS impact

OSVersionStatusFixed in
freebsd freebsd8.4affected
freebsd freebsd9.0affected
freebsd freebsd9.1affected
freebsd freebsd9.2affected
freebsd freebsd9.3affected
freebsd freebsd10.0affected
freebsd freebsd10.1affected

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.