PT-2018-3551 · Freebsd · Freebsd

Maxime Villard

·

Publicado

2018-03-07

·

Atualizado

2018-03-29

·

CVE-2018-6916

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FreeBSD versions prior to 11.1-STABLE FreeBSD versions prior to 11.1-RELEASE-p7 FreeBSD versions prior to 10.4-STABLE FreeBSD versions prior to 10.4-RELEASE-p7 FreeBSD versions prior to 10.3-RELEASE-p28
Description: The issue is related to the kernel's improper validation of IPsec packets from a trusted host and a use-after-free vulnerability in the IPsec AH handling code. This could lead to a system crash or other unpredictable results. The vulnerability may also allow a remote attacker to execute arbitrary code.
Recommendations: For versions prior to 11.1-STABLE, update to 11.1-STABLE or later. For versions prior to 11.1-RELEASE-p7, update to 11.1-RELEASE-p7 or later. For versions prior to 10.4-STABLE, update to 10.4-STABLE or later. For versions prior to 10.4-RELEASE-p7, update to 10.4-RELEASE-p7 or later. For versions prior to 10.3-RELEASE-p28, update to 10.3-RELEASE-p28 or later.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04498
CVE-2018-6916
FREEBSD-SA-18_01

Produtos afetados

Freebsd