In FreeBSD, remotely exploitable vulnerabilities in ipfw have been addressed

In the ipfw packet filter risolte two vulnerabilities in the TCP options parsing code, caused by inadequate data verification in processed network packets. The first vulnerability (CVE-2019-5614) can lead to access to memory outside the allocated mbuf buffer when processing specially crafted TCP packets, while the second (CVE-2019-15874) can result in access to already freed memory areas (use-after-free).

An analysis of the suitability of the identified issues for exploitation capable of initiating the execution of malicious code has not been conducted, but it cannot be ruled out that the vulnerabilities may extend beyond just causing kernel crashes. The issues have been fixed in updates for FreeBSD 11.3-RELEASE-p8 and 12.1-RELEASE-p4 (corrections were introduced in the stable branches back in December of last year, but it was only recently revealed that these fixes are related to resolving vulnerabilities).

Fonte: opennet.ru

Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS 🔥 Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS | ProHoster