Three vulnerabilities have been fixed in FreeBSD

Three vulnerabilities have been fixed in FreeBSD that allow code execution when using libfetch, the retransmission of IPsec packets, or access to kernel data. The issues have been resolved in updates 12.1-RELEASE-p2, 12.0-RELEASE-p13, and 11.3-RELEASE-p6.

  • CVE-2020-7450 — a buffer overflow in the libfetch library used for downloading files in the fetch command, the pkg package manager, and other utilities. This vulnerability can lead to code execution when processing specially crafted URLs. An attack can be carried out by accessing a maliciously controlled website that can initiate the processing of a malicious URL through HTTP redirection;
  • CVE-2019-15875 — a vulnerability in the core dump generation mechanism of processes. Due to a bug, core dumps could record up to 20 bytes of data from the kernel stack, which might contain sensitive information being processed by the kernel. As a workaround for protection, core file generation can be disabled through sysctl kern.coredump=0;
  • CVE-2019-5613 — an error in the code for blocking the retransmission of data in IPsec allowed for the replaying of previously captured packets. Depending on the high-level protocol transmitted over IPsec, the identified problem could allow, for example, the replaying of previously sent commands.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster