PT-2017-2031 · Freebsd · Freebsd

Dmitry Chagin

·

Publicado

2016-01-14

·

Atualizado

2018-01-30

·

CVE-2016-1881

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD versions 9.3, 10.1, and 10.2
Description The issue is related to insufficient access control in the FreeBSD kernel, which can be exploited to cause a denial of service or potentially gain privileges. This can be achieved by making a specially crafted Linux compatibility layer setgroups system call.
Recommendations For versions 9.3, 10.1, and 10.2, consider restricting access to the Linux compatibility layer to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the setgroups system call until a fix is provided.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01198
CVE-2016-1881
FREEBSD-SA-16_04

Produtos afetados

Freebsd