In the ftpd server included with FreeBSD a critical vulnerability (CVE-2020-7468) that allows users limited to their home directory using the ftpchroot option to gain full root access to the system.
The issue is caused by a combination of an error in the implementation of the user isolation mechanism via the chroot call (non-fatal errors were returned during uid changes or executing chroot and chdir that did not terminate the session) and granting authenticated FTP users sufficient rights to bypass the root path restriction in the filesystem. The vulnerability does not manifest when accessing the FTP server in anonymous mode or when a user logs in without ftpchroot. The issue has been resolved in updates 12.1-RELEASE-p10, 11.4-RELEASE-p4, and 11.3-RELEASE-p14.
Additionally, it is worth noting the resolution of three more vulnerabilities in 12.1-RELEASE-p10, 11.4-RELEASE-p4, and 11.3-RELEASE-p14:
- — a vulnerability in the Bhyve hypervisor that allows information to be written from the guest environment to the memory areas of the host environment, granting full access to the host system. This issue arises from the lack of access restrictions to processor instructions handling physical addresses of the host and appears only on systems with AMD CPUs.
- — a vulnerability in the Bhyve hypervisor that allows an attacker with root rights inside isolated environments managed by Bhyve to execute code at the kernel level. This problem is due to inadequate access restrictions to VMCS (Virtual Machine Control Structure) on Intel CPU systems and VMCB (Virtual Machine Control Block) on AMD CPU systems.
CVE-2020-7464 - Release BlendNet 0.3, an add-on for distributed rendering setup
Source: opennet.ru
