PT-2011-1042 · Debian+1 · Kfreebsd-8+1
Mateusz Guzik
·
Publicado
2011-10-18
·
Atualizado
2011-12-13
·
CVE-2011-4062
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kfreebsd-8 versions (affected versions not specified)
FreeBSD versions 7.3 through 9.0-RC1
Description
The issue concerns multiple vulnerabilities in the kfreebsd-8 package of the Debian GNU/Linux operating system and a buffer overflow in the kernel of FreeBSD. These vulnerabilities can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The buffer overflow vulnerability can cause a denial of service or possibly allow privilege escalation via a bind system call with a long pathname for a UNIX socket.
Recommendations
For kfreebsd-8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For FreeBSD versions 7.3 through 9.0-RC1, consider upgrading to a version later than 9.0-RC1 to resolve the buffer overflow issue. As a temporary workaround, consider restricting access to the bind system call to minimize the risk of exploitation.
Exploit
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freebsd
Kfreebsd-8