FreeBSD Kernel sys_amd64 IRET Handler Flaw Lets Local Users Deny Service or Gain Elevated Privileges : 8/26/2015 3:28:05 AM

This eBook shows you how common web marketing tactics map to their mobile counterparts, including a "this = that" chart of web to app equivalents.
From our sponsors
 

 

Vulnerability Databse
This module replaces the description field of a feed to the page it links to (in addition, it wipes out the content:encoded field), so you can get its full text.

FreeBSD Kernel sys_amd64 IRET Handler Flaw Lets Local Users Deny Service or Gain Elevated Privileges
8/26/2015 12:00:00 AM

FreeBSD Kernel sys_amd64 IRET Handler Flaw Lets Local Users Deny Service or Gain Elevated Privileges
SecurityTracker Alert ID:  1033376
SecurityTracker URL:  http://securitytracker.com/id/1033376
CVE Reference:   CVE-2015-5675   (Links to External Site)
Date:  Aug 26 2015
Impact:   Denial of service via local system, User access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 9.3, 10.1
Description:   A vulnerability was reported in FreeBSD. A local user can cause denial of service conditions on the target system. A local user can obtain elevated privileges on the target system.

A local user can trigger a return from interrupt (IRET) with #SS or #NP exceptions to gain elevated privileges or cause a kernel panic.

Konstantin Belousov and Andrew Lutomirski reported this vulnerability.

Impact:   A local user can cause denial of service conditions on the target system.

A local user can obtain elevated privileges on the target system.

Solution:   FreeBSD has issued a fix.

The FreeBSD advisory is available at:

https://security.FreeBSD.org/advisories/FreeBSD-SA-15:21.amd64.asc

Vendor URL:  security.FreeBSD.org/advisories/FreeBSD-SA-15:21.amd64.asc (Links to External Site)
Cause:   Access control error
Underlying OS:  

Message History:   None.

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

Diberdayakan oleh Blogger.