In FreeBSD sono state eliminate 6 vulnerabilità.

In FreeBSD, six vulnerabilities have been fixed that allow for privilege escalation in the system or access to kernel data. The issues have been addressed in updates 12.0-RELEASE-p8, 11.2-RELEASE-p12, and 11.3-RELEASE-p1.

  • CVE-2019-5606 — a flaw in the close call handler for file descriptors created through the posix_openpt system call may lead to writes in already freed areas of kernel memory (write-after-free). A local attacker can exploit this vulnerability to gain root privileges or to escape from a jail environment;
  • CVE-2019-0053 — inadequate validation of values when processing environment variables in the telnet client code may lead to a buffer overflow when connecting to a malicious server, allowing for client-side code execution attacks;
  • CVE-2019-5605 — a flaw in the implementation of freebsd32_ioctl may lead to the leaking of areas of kernel memory that could potentially contain residual data from the terminal buffer or file cache;
  • CVE-2019-5603 — possibilità di provocare un overflow del contatore nel pseudo-FS mqueuefs, che può essere usato per accedere a file, directory e socket di altri processi appartenenti ad altri utenti. Questo problema può anche permettere l'uscita da un jail e, in caso di accesso root nel jail, ottenere privilegi root nel sistema principale;
  • CVE-2019-5604 — errore di verifica dei valori dei parametri ‘epid’ e ‘streamid’ nel codice di emulazione dei dispositivi XHCI nel hypervisor bhyve consente di identificare valori di memoria al di fuori del buffer allocato o provocare un crash del sistema;
  • CVE-2019-5607 — perdita del contatore dei riferimenti ai descrittori di socket UNIX, utilizzati per il passaggio di privilegi tra processi, può essere usata per ottenere accesso root o uscire da un ambiente di jail.

Fonte: opennet.ru

Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS 🔥 Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS | ProHoster