Vulnerability in the FreeBSD version of OpenSSH allows for remote code execution.

A vulnerability has been identified in the OpenSSH server included with FreeBSD (CVE-2024-7589), allowing for remote code execution with root privileges without authentication. This vulnerability is a variant of the issue found earlier in July in OpenSSH (CVE-2024-6387) and is also caused by a race condition arising from executing functions in signal handlers that are not designed to be called asynchronously.

The FreeBSD developers addressed the original July vulnerability immediately after it was announced, but the fix did not cover all potential attack vectors. The fix involved disabling the sshlogv function call, which allocates memory dynamically. This could lead to corruption of malloc's internal structures during asynchronous execution when the SIGALRM signal handler was triggered while certain code was running. It turned out that a similar problem arose in the FreeBSD-specific invocation of the blacklist_notify function, which integrates with the background process blacklistd.

In addition to applying the patch, the vulnerability can be blocked by setting the parameter "LoginGraceTime=0" in /etc/ssh/sshd_config. However, disabling the timeout would simplify the initiation of denial-of-service attacks when establishing a large number of connections that exceed the limits set by the MaxStartups parameter.

In addition, three more vulnerabilities have been fixed in FreeBSD:

  • CVE-2024-6760 — a bypass of the ktrace protection for tracing suid processes, allowing an unprivileged user to access the contents of files that they do not have permission to read, for example, it is possible to read the contents of a file containing user password hashes.
  • CVE-2024-6759 — a potential issue was found in the NFS client allowing the use of path separator characters ".." and "\/" in file names;
  • CVE-2024-6640 — a vulnerability in the PF packet filter, causing ICMPv6 packets with a zero identifier to bypass firewall rules designed for incoming packets reflected in the state table.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster