Six vulnerabilities have been fixed in FreeBSD

Six vulnerabilities have been fixed in FreeBSD, which allow for privilege escalation or access to kernel data. The issues have been addressed in updates 12.0-RELEASE-p8, 11.2-RELEASE-p12, and 11.3-RELEASE-p1.

  • CVE-2019-5606 — A flaw in the close call handler for file descriptors created via the posix_openpt system call can lead to writing to already freed areas of kernel memory (write-after-free). A local attacker can exploit this vulnerability to gain root privileges or escape a jail environment;
  • CVE-2019-0053 — Insufficient validation of values when processing environment variables in the telnet client code can lead to a buffer overflow when connecting to a malicious server, enabling a code execution attack on the client side;
  • CVE-2019-5605 — A bug in the implementation of freebsd32_ioctl can lead to leakage of kernel memory areas that may contain residual data from terminal buffers or file caches;
  • CVE-2019-5603 — A possibility to trigger a counter overflow in the pseudo-filesystem mqueuefs, which can be exploited to gain access to files, directories, and sockets of other processes owned by different users. This issue may be used to escape a jail, and if root access is available in the jail, to gain root privileges on the host system;
  • CVE-2019-5604 — A bug in the validation of the parameters ‘epid’ and ‘streamid’ in the XHCI device emulation code within the bhyve hypervisor allows for accessing memory values beyond the allocated buffer or causing a system crash;
  • CVE-2019-5607 — A leak of reference counts on UNIX socket descriptors used for privilege transmission between processes can be exploited to gain root access or escape a jail environment.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster