Several vulnerabilities have been fixed in FreeBSD that allow a local user to escalate their privileges in the system:
- — a vulnerability in the posix_spawnp mechanism provided in libc for process creation, exploited by specifying an excessively large value in the PATH environment variable. This vulnerability can lead to writing data outside the memory area allocated for the stack, allowing the content of subsequent buffers to be overwritten with a controlled value.
- — a vulnerability in the IPv6 stack that allows a local user to execute their code at the kernel level through manipulations using the IPV6_2292PKTOPTIONS option for a network socket.
- Fixed (CVE-2020-12662, CVE-2020-12663) in the bundled DNS server , allowing remote denial of service when contacting a server controlled by an attacker or using the DNS server as a traffic amplifier in DDoS attacks.
Additionally, three non-security related issues (errata) have been fixed that may lead to kernel crashes while using the driver (when executing the sas2ircu command), the subsystem (when redirecting X11) and the hypervisor (when passing through PCI devices).
Source: opennet.ru
