In FreeBSD, several vulnerabilities have been fixed that allow a local user to elevate their privileges in the system:
- — a vulnerability in the posix_spawnp mechanism provided in libc for creating processes, exploited by specifying an excessively large value in the PATH environment variable. This vulnerability can lead to writing data outside the memory area allocated for the stack and can overwrite the contents of subsequent buffers with controlled values.
- — a vulnerability in the IPv6 stack that allows a local user to execute their code at the kernel level through manipulations using the IPV6_2292PKTOPTIONS option for a network socket.
- Risolti (CVE-2020-12662, CVE-2020-12663) in the supplied DNS server, , allowing for a remote denial of service when communicating with a server controlled by an attacker or using the DNS server as a traffic amplifier in DDoS attacks.
Additionally, three non-security related issues (errata) have been fixed that could lead to kernel crashes while using the (nell'esecuzione del comando sas2ircu), subsistemi (nella redirezione di X11) e hypervisor (nella pass-through di dispositivi PCI).
Fonte: opennet.ru
