Vulnerabilities in libc and the IPv6 stack of FreeBSD

Several vulnerabilities have been fixed in FreeBSD that allow a local user to escalate their privileges in the system:

  • CVE-2020-7458 — a vulnerability in the posix_spawnp mechanism provided in libc for process creation, exploited by specifying an excessively large value in the PATH environment variable. This vulnerability can lead to writing data outside the memory area allocated for the stack, allowing the content of subsequent buffers to be overwritten with a controlled value.
  • CVE-2020-7457 — a vulnerability in the IPv6 stack that allows a local user to execute their code at the kernel level through manipulations using the IPV6_2292PKTOPTIONS option for a network socket.
  • Fixed were fixed in Salt (CVE-2020-12662, CVE-2020-12663) in the bundled DNS server Unbound, allowing remote denial of service when contacting a server controlled by an attacker or using the DNS server as a traffic amplifier in DDoS attacks.

Additionally, three non-security related issues (errata) have been fixed that may lead to kernel crashes while using the driver mps (when executing the sas2ircu command), the subsystem LinuxKPI (when redirecting X11) and the hypervisor bhyve (when passing through PCI devices).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster