★ wanayoo — archive 1999 http://search.linuxsecurity.com/advisories/freebsd.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Caldera
Corel
Debian
FreeBSD
LinuxPPC
Mandrake
NetBSD
OpenBSD
Other
Red Hat
Slackware
Stampede
StormLinux
SuSE
TurboLinux
 
FreeBSD 2/28/2001 10:20


  • 2/28/2001 10:20 : FreeBSD: 'sunrpc' DoS
    - Chris Evans has reported a possible DoS in the sunrpc code: A well known bug I first publicised back in 1998 still exists in the FreeBSD libc sunrpc code. Linux glibc, OpenBSD and possibly even Sun fixed the problem back in 1998.

  • 2/14/2001 13:51 : FreeBSD: 'libkrb' and 'telnetd' vulnerabilities
    - The advisory describes three vulnerabilities in the Kerberos libraries.

  • 2/7/2001 17:03 : FreeBSD: 'mars_nwe' ports vulnerability
    - The mars_nwe port, versions prior to 0.99.b19_1, contains a remote format string vulerability.

  • 2/7/2001 17:02 : FreeBSD: 'dc20ctrl' ports vulnerability
    - The dc20ctrl port, versions prior to 0.4_1, contains a locally exploitable buffer overflow.

  • 2/7/2001 17:01 : FreeBSD: 'ja-elvis' and 'ko-helvis' ports vulnerability
    - The ja-elvis and ko-helvis ports, versions prior to ja-elvis-1.8.4_1 and ko-helvis-1.8h2_1, contain an exploitable buffer overflow in the elvrec utility.

  • 2/7/2001 16:59 : FreeBSD: 'ja-xklock' ports vulnerability
    - The ja-xklock port, versions 2.7.1 and earlier, contains an exploitable buffer overflow.

  • 2/7/2001 14:37 : FreeBSD: 'bind' vulnerabilies [UPDATED]
    - NOTE: It has come to our attention that there are a great deal more users downloading this advisory than the recently released SA-01:18, which also deals with the bind software. The latter advisory details a far more serious vulnerability.

  • 2/1/2001 11:23 : FreeBSD: 'bind' vulnerabilities
    - An overflowable buffer related to the processing of transaction signatures (TSIG) exists in all versions of BIND prior to 8.2.3-RELEASE.

  • 1/30/2001 10:49 : FreeBSD: 'exmh2' port vulnerability
    - The exmh2 port, versions prior to 2.3.1, contains a local vulnerability.

  • 1/30/2001 10:48 : FreeBSD: 'mysql' ports vulnerability
    - The mysql323-server port, versions prior to 3.23.22, and all mysql322-server ports contain remote vulerabilities.

  • 1/30/2001 10:47 : FreeBSD: 'tinyproxy' ports vulnerability
    - The tinyproxy port, versions prior to 1.3.3a, contains several remotely exploitable vulnerabilities.

  • 1/30/2001 10:46 : FreeBSD: 'micq' ports buffer overflow
    - The micq port, versions prior to 0.4.6.1, contains a remotely exploitable buffer overflow.

  • 1/29/2001 16:36 : FreeBSD: 'sort' creates insecure temp files
    - During internal auditing, sort(1) was found to use easily predictable temporary file names.

  • 1/29/2001 15:53 : FreeBSD: 'periodic' vulnerability
    - A vulnerability was inadvertently introduced into periodic that caused temporary files with insecure file names to be used in the system's temporary directory.

  • 1/29/2001 15:51 : FreeBSD: 'ident' vulnerability
    - The internal ident server in inetd was found to incorrectly set group privileges according to the user. This allows a malicious user to read the first 16 byes of wheel-accessible files.

  • 1/25/2001 0:52 : FreeBSD: UPDATE: 'crontab' vulnerability
    - crontab allows users to read certain files

  • 1/24/2001 10:59 : FreeBSD: 'bind' remote DoS
    - Malicious remote users can cause the named daemon to crash, if it is configured to allow zone transfers and recursive queries.

  • 1/23/2001 19:37 : FreeBSD: 'crontab' vulnerability
    - Malicious local users can read arbitrary local files that conform to a valid crontab file syntax.

  • 1/23/2001 19:28 : FreeBSD: Several 'XFree86' ports vulnerabilities
    - Local or remote users may cause a denial of service attack against an X server or certain X applications. Local users may obtain elevated privileges with certain X applications.

  • 1/23/2001 16:17 : FreeBSD: 'ipfw/ip6fw' vulnerability
    - Due to overloading of the TCP reserved flags field, ipfw and ip6fw incorrectly treat all TCP packets with the ECE flag set as being part of an established TCP connection.

  • 1/15/2001 18:56 : FreeBSD: 'openssh' vulnerability
    - The openssh client fails to check whether agent or X11 forwarding has been negotiated during session setup.

  • 1/15/2001 18:54 : FreeBSD: 'syslog-ng' remote DoS
    - Due to incorrect log parsing, remote users may cause syslog-ng to crash.

  • 1/15/2001 18:53 : FreeBSD: 'bash1' creates insecure temporary file
    - An attacker can exploit this vulnerability to overwrite an arbitrary file writable by the user running the shell.

  • 1/15/2001 18:52 : FreeBSD: 'joe' creates insecure recovery files
    - Potential symlink attack exists with previous versions.

  • 1/15/2001 18:48 : FreeBSD: 'stunnel' root compromise potential
    - An incorrect usage of syslog() in older versions may lead to root compromise.

  • 1/15/2001 18:46 : FreeBSD: 'zope' privilege escalation vulnerability
    - This may allow users with privileges in one folder to gain the same privileges in another folder.

  • 12/29/2000 10:48 : FreeBSD: 'procfs' vulnerabilities [UPDATED]
    - There were several problems discovered in the procfs code

  • 12/29/2000 9:27 : FreeBSD: 'bitchx' and 'ko-bitchx' vulnerability [UPDATED]
    - The bitchx port, versions prior to 1.0c17_1, and ko-bitchx port, versions prior to 1.0c16_3, contains a remote vulnerability.

  • 12/20/2000 10:35 : FreeBSD: 'ethereal' ports vulnerability
    - The ethereal port, versions prior to 0.8.14, contains buffer overflows which allow a remote attacker to crash ethereal or execute arbitrary code on the local system.

  • 12/20/2000 10:10 : FreeBSD: "halflifeserver' ports vulnerability
    - The halflifeserver port, versions prior to 3.1.0.4, contains local and remote vulnerabilities through buffer overflows and format string vulnerabilities.

  • 12/20/2000 9:56 : FreeBSD: 'bitchx' ports vulnerability
    - The bitchx port, versions prior to 1.0c17_1, contains a remote vulnerability.

  • 12/20/2000 9:56 : FreeBSD: 'oops' port vulnerability
    - The oops port, versions prior to 1.5.2, contains remote vulnerabilities through buffer and stack overflows in the HTML parsing code.

  • 12/18/2000 10:39 : FreeBSD: 'procps' vulnerability
    - There were several problems discovered in the procfs code.

  • 11/20/2000 18:21 : FreeBSD: 'tcsh/csh' vulnerability
    - The csh and tcsh code creates predictable temporary files when the '<<' operator is used.

  • 11/20/2000 18:20 : FreeBSD: 'ncurses' vulnerability
    - There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities.

  • 11/20/2000 18:18 : FreeBSD: 'telnet' vulnerability
    - The telnet protocol allows some environmental variables to affect its operation.

  • 11/20/2000 18:16 : FreeBSD: 'php' ports vulnerability
    - The mod_php ports, versions prior to 3.0.17 and 4.0.3 contain a potential vulnerablilty that may allow a malicious remote user to execute arbitrary code.

  • 11/20/2000 18:14 : FreeBSD: 'thttpd' ports vulnerability
    - The thttpd port, versions prior to 2.20, allows remote viewing of arbitrary files on the local server.

  • 11/20/2000 17:38 : FreeBSD: 'curl' vulnerability
    - The curl port, versions prior to 7.4.1, allows a client-side exploit through a buffer overflow in the error handling code.

  • 11/20/2000 17:37 : FreeBSD: 'mgetty' vulnerability
    - The mgetty port, versions prior to 1.1.22.8.17, contains a vulnerability that may allow local users to create or overwrite any file on the system.

  • 11/14/2000 18:21 : FreeBSD: 'ppp deny_incoming' vulnerability
    - ppp "deny_incoming" does not correctly deny incoming packets.

  • 11/14/2000 18:19 : FreeBSD: 'telnetd' vulnerability
    - Of particular relevance is the ability for remote users to cause an arbitrary file on the system to be searched for termcap data by passing the TERMCAP environment variable.

  • 11/13/2000 18:58 : FreeBSD: 'ncurses' vulnerability
    - There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities.

  • 11/10/2000 18:46 : FreeBSD: 'gnupg' ports vulnerability
    - Versions of gnupg prior to 1.04 fail to correctly verify multiple signatures contained in a single document.

  • 11/7/2000 15:39 : FreeBSD: 'netscape' ports vulnerability
    - Versions of netscape prior to 4.76 allow a client-side exploit through a buffer overflow in html code.

  • 11/7/2000 15:36 : FreeBSD: 'xfce' ports vulnerability
    - Versions of xfce prior to 3.52 contain a startup script which incorrectly allows access to the X display to all other users on the local system.

  • 11/6/2000 18:24 : FreeBSD: 'global' root compromise
    - global port allows remote compromise through CGI script

  • 11/6/2000 18:23 : FreeBSD: 'top' vulnerability
    - top allows reading of kernel memory [REISSUED]

  • 11/6/2000 18:22 : FreeBSD: 'tcpdump' vulnerability
    - tcpdump contains remote vulnerabilities [REISSUED]

  • 11/1/2000 18:23 : FreeBSD: 'getnameinfo' vulnerability
    - An off-by-one error exists in the processing of DNS hostnames which allows a long DNS hostname to crash the getnameinfo() function under certain conditions.

  • 11/1/2000 18:21 : FreeBSD: 'top' vulnerability
    - A "format string vulnerability" was discovered in the top(1) utility which allows unprivileged local users to cause the top process to execute arbitrary code.

  • 10/30/2000 18:59 : FreeBSD: 'tcpdump' vulnerability
    - Several overflowable buffers were discovered in the version of tcpdump included in FreeBSD.

  • 10/30/2000 18:58 : FreeBSD: 'boa' vulnerability
    - The boa port, versions after 0.92 but prior to 0.94.8.3, contains a vulnerability which allows remote users to view arbitrary files outside the document root.

  • 10/30/2000 18:57 : FreeBSD: 'pine' vulnerability
    - The pine4 port, versions 4.21 and before, contains a buffer overflow vulnerability.

  • 10/30/2000 18:55 : FreeBSD: 'chpass' vulnerability
    - A "format string vulnerability" was discovered in code used by the vipw utility during an internal FreeBSD code audit in July 2000.

  • 10/13/2000 12:33 : FreeBSD: 'muh' ports vulnerability
    - The muh port, versions 2.05c and before, contains a vulnerability which allows remote users to gain the privileges of the user running muh.

  • 10/13/2000 12:30 : FreeBSD: 'fingerd' vulnerability
    - A malicious user may be able to read certain files via a finger request.

  • 10/13/2000 12:29 : FreeBSD: 'LPRng' ports vulnerability
    - The LPRng port, versions prior to 3.6.24, contains a potential vulnerability which may allow root compromise from both local and remote systems.

  • 10/13/2000 12:28 : FreeBSD: 'xpdf' ports vulnerability
    - The xpdf port, versions prior to 0.91, contains a race condition due to improper handing of temporary files.

  • 10/6/2000 18:43 : FreeBSD: TCP sequence number predication weakness
    - TCP uses weak initial sequence numbers

  • 9/27/2000 21:51 : FreeBSD: 'catopen()' vulnerability
    - catopen() and setlocale() are functions which are used to display text in a localized format, e.g. for international users.

  • 9/20/2000 17:26 : FreeBSD: 'screen' update
    - The screen port, versions 3.9.5 and before, contains a vulnerability which allows local users to gain root privileges.

  • 9/13/2000 17:00 : FreeBSD: 'mailman' vulnerability
    - The mailman port, versions prior to 2.0b5, contained several locally exploitable vulnerabilities which could be used to gain root privileges.

  • 9/13/2000 16:57 : FreeBSD: 'listmanager' vulnerability
    - The listmanager port, versions prior to 2.105.1, contained several locally exploitable buffer overflow vulnerabilities which could be used to gain root privileges.

  • 9/13/2000 16:56 : FreeBSD: 'eject' vulnerability
    - The eject program is installed setuid root, and contains several exploitable buffers which can be overflowed by local users, yielding root privileges.

  • 9/13/2000 16:47 : FreeBSD: 'xchat' vulnerability
    - Prior to version 1.5.7 in the 1.5 development series, a malicious IRC user could embed command strings in a URL.

  • 9/13/2000 16:44 : FreeBSD: 'pine4' vulnerability
    - The pine4 port, versions 4.21 and before, contained a bug which would cause the program to crash when processing a folder which contains an email message with a malformed X-Keywords header.

  • 9/13/2000 16:42 : FreeBSD: 'screen' vulnerability
    - The screen port, versions 3.9.5 and before, contains a vulnerability which allows local users to gain root privileges.

  • 8/31/2000 15:03 : FreeBSD: 'esound' vulnerability.
    - The esound port, versions 0.2.19 and earlier, creates a world-writable directory in /tmp owned by the user running the EsounD session

  • 8/29/2000 9:33 : FreeBSD: Malformed ELF image vulnerability
    - The ELF binary format is used for binary executable programs on modern versions of FreeBSD.

  • 8/28/2000 19:59 : FreeBSD: mopd remote root compromise
    - The mopd port contains several remotely exploitable vulnerabilities. An attacker exploiting these can execute arbitrary code on the local machine as root.

  • 8/28/2000 19:59 : FreeBSD: Netscape vulnerabilities
    - Remote users can read files on the local system accessible to the user running netscape, if java is enabled, and may be able to execute arbitrary code on the local system as that user.

  • 8/28/2000 19:57 : FreeBSD: Local DoS vulnerability
    - Malformed ELF images can cause a system hang

  • 8/28/2000 19:55 : FreeBSD: Linux binary compatibility vulnerability
    - Linux binary compatability mode can cause system compromise

  • 8/28/2000 19:54 : FreeBSD: brouted vulnerability
    - brouted port allows gid kmem compromise

  • 8/28/2000 19:53 : FreeBSD: xlockmore vulnerability
    - xlockmore port allows reading of password file

  • 8/14/2000 20:55 : FreeBSD: zope vulerability
    - zope is an object-based dynamic web application platform.

  • 8/14/2000 20:54 : FreeBSD: cvsweb vulnerability
    - cvsweb is a CGI script which provides a read-only interface to a CVS repository for browsing via a web interface.

  • 8/14/2000 20:52 : FreeBSD: ntop vulnerability
    - ntop is a utility for monitoring and summarizing network usage, from the command-line or remotely via HTTP.

  • 8/14/2000 20:51 : FreeBSD: proftpd vulnerability
    - The proftpd port, versions prior to 1.2.0rc2, contains a vulnerability which allows FTP users, both anonymous FTP users and those with a valid account, to execute arbitrary code as root on the local machine,

  • 8/14/2000 20:49 : FreeBSD: dhclient vulnerability
    - dhclient is vulnerable to malicious dhcp server.

  • 8/8/2000 14:28 : FreeBSD: Security Advisory distribution corrected
    - FreeBSD advisory delivery clarification

  • 7/14/2000 10:53 : FreeBSD: Multiple kerberosIV vulnerabilities
    - Local or remote users can obtain root access on the system running Kerberos, whether as client or server.

  • 7/12/2000 18:48 : FreeBSD: UPDATE: wu-ftpd port contains remote root compromise
    - FTP users, including anonymous FTP users, can cause arbitrary commands to be executed as root on the local machine.

  • 7/12/2000 14:27 : FreeBSD: UPDATE: Canna port contains remote vulnerability
    - Remote users can run arbitrary code as user 'bin' on the local system.

  • 7/12/2000 14:26 : FreeBSD: UPDATE: popper port contains remote vulnerability
    - Remote users can cause arbitrary code to be executed as the retrieving user when a POP client retrieves email.

  • 7/12/2000 14:25 : FreeBSD: UPDATE: Remote denial-of-service in IP stack
    - Remote users can cause a FreeBSD system to panic and reboot.

  • 7/6/2000 10:49 : FreeBSD: popper port contains remote vulnerability
    - Remote users can cause arbitrary code to be executed as the retrieving user when a POP client retrieves email.

  • 7/6/2000 10:48 : FreeBSD: libedit vulnerability
    - libedit reads config file from current directory leading to potential root compromise.

  • 7/6/2000 10:47 : FreeBSD: OpenSSH root vulnerability
    - OpenSSH UseLogin directive permits remote root access

  • 7/6/2000 10:46 : FreeBSD: Majordomo vulnerability
    - majordomo is not safe to run on multi-user machines

  • 7/6/2000 10:45 : FreeBSD: bitchx port contains client-side vulnerability
    - Remote IRC users can cause the local client to crash, and possibly execute code as the local user.

  • 7/6/2000 10:44 : FreeBSD: XFree86-4.0 port contains local root overflow
    - Unprivileged local users can obtain root access.

  • 7/6/2000 10:44 : FreeBSD: Canna port remote vulnerability
    - Remote users can run arbitrary code as user 'bin' on the local system.

  • 7/6/2000 10:43 : FreeBSD: wu-ftpd port contains remote root compromise
    - Remote anonymous FTP users can cause arbitrary commands to be executed as root on the local machine.

  • 6/22/2000 22:20 : FreeBSD: Remote denial-of-service in IP stack
    - Remote users can cause a FreeBSD system to panic and reboot.

  • 6/12/2000 20:37 : FreeBSD: Alpha port vulnerability
    - FreeBSD/Alpha platform lacks kernel pseudo-random number generator, some applications fail to detect this.

  • 6/8/2000 11:11 : FreeBSD: ssh port listens on extra network port [REVISED]
    - Remote users with valid SSH credentials may access the ssh server on a non-standard port

  • 6/8/2000 11:10 : FreeBSD: apsfilter allows users to execute arbitrary commands
    - Local users can cause arbitrary commands to be executed as root

  • 5/28/2000 14:14 : FreeBSD: krb5 port contains remote and local root exploits.
    - Local or remote users can obtain root access on the system running krb5.

  • 5/28/2000 14:13 : FreeBSD: Local users can prevent all processes from exiting
    - An unprivileged local user can cause every process on the system to hang during exiting.

  • 5/17/2000 18:14 : FreeBSD: gnapster/knapster vulnerabilities
    - gnapster/knapster ports allows remote users to view local files

  • 5/17/2000 17:48 : FreeBSD: Lynx buffer overflows
    - Lynx ports contain numerous buffer overflows

  • 5/9/2000 15:51 : FreeBSD: gnapster port allows remote users to view local files
    - The gnapster port (version 1.3.8 and earlier) contains a vulnerability which allows remote gnapster users to view any file on the local system which is accessible to the user running gnapster.

  • 5/9/2000 15:49 : FreeBSD: golddig port allows users to overwrite local files
    - The golddig port erroneously installs a level-creation utility setuid root, which allows users to overwrite the contents of arbitrary local files.

  • 5/9/2000 15:48 : FreeBSD: Buffer overflow in libmytinfo
    - libmytinfo allows users to specify an alternate termcap file or entry via the TERMCAP environment variable, however this is not handled securely and contains a overflowable buffer inside the library.

  • 4/24/2000 14:28 : FreeBSD: imap-uw service denial
    - imap-uw allows local users to deny service to any mailbox

  • 4/24/2000 14:26 : FreeBSD : imap-uw vulnerability
    - imap-uw contains security vulnerabilities for "closed" mail servers

  • 4/19/2000 1:09 : FreeBSD: generic-nqs contains a local root compromise
    - Generic-NQS versions 3.50.7 and earlier contain a security vulnerability which allow a local user to easily obtain root privileges.

  • 3/19/2000 0:58 : mh/nmh/exmh/exmh2
    - Revision -- The mhshow command used for viewing MIME attachments contains a buffer overflow which can be exploited by a specially-crafted email attachment, which will allow the execution of arbitrary code as the local user when the attachment is opened.

  • 3/17/2000 0:34 : FreeBSD: mh and others exploit
    - mh/nmh/ja-mh/exmh/exmh2/ja-exmh2 ports allow remote execution of binary code.

  • 3/17/2000 0:32 : FreeBSD: orville-write local root compromise
    - orville-write port contains local root compromise.

  • 3/16/2000 0:31 : FreeBSD: lynx buffer overflows
    - Lynx ports contain numerous buffer overflows

  • 3/16/2000 0:30 : FreeBSD: mtr local root exploit
    - mtr port contains a local root exploit.

  • 3/1/2000 8:13 : FreeBSD: MySQL allows bypassing of password authentication
    - The MySQL database server (versions prior to 3.22.32) has a flaw in the password authentication mechanism which allows anyone who can connect to the server to access databases without requiring a password, given a valid username on the database - in other words, the normal password authentication mechanism can be completely bypassed.

  • 2/21/2000 21:02 : FreeBSD: Delegate port contains numerous buffer overflows
    - An optional third-party port distributed with FreeBSD contains numerous remotely- exploitable buffer overflows which allow an attacker to execute arbitrary commands on the local system, typically as the 'nobody' user.

  • 2/21/2000 16:12 : FreeBSD: Asmon/Ascpu ports fail to drop privileges
    - Two optional third-party ports distributed with FreeBSD can be used to execute commands with elevated privileges, specifically setgid kmem privileges. This may lead to a local root compromise.

  • 9/16/1999 17:58 : FreeBSD-SA-99:06:remote amd attack
    - There are two buffer overflow vulnerabilities in the the amd daemon

  • 9/15/1999 17:58 : FreeBSD-SA-99:05:fts library routine vulnerability
    - The fts library functions had a buffer overflow in them where which would lead to a core dump when periodic ran the security checking scripts (or other scripts which traverse trees that can be controlled by users). periodic(3) should limit core size to zero to disable core dumps while it is executing commands, but does not do so. In addition, the kernel should not follow symbolic links. All three of these problems caused a situation where it was possible for an attacker could create or overwrite an arbitrary file on the system with a moderate degree of controll of its contents to cause a problem.

  • 9/15/1999 17:58 : FreeBSD-SA-99:04:Coredumps and symbolic links
    - The fts library functions had a flaw in them where which would lead to a core dump when periodic ran the security checking scripts (or other scripts which traverse trees that can be controlled by users). periodic(3) should limit core size to zero to disable core dumps while it is executing commands, but does not do so. In addition, the kernel should not follow symbolic links. All three of these problems caused a situation where it was possible for an attacker could create or overwrite an arbitrary file on the system with a moderate degree of controll of its contents to cause a problem.

  • 9/5/1999 17:58 : FreeBSD-SA-99:03:Three ftp daemons in ports vulnerable to attack.
    - There are different security problems which can lead to remote root access in these ports or packages. The standard ftp daemon which ships with FreeBSD is not impacted by either of these problems.

  • 9/4/1999 17:57 : FreeBSD-SA-99:02:Profiling Across Exec Calls
    - A flaw exists in the implementation which allows an attacker to cause arbitrary locations in program executed by the attacker.

  • 9/4/1999 17:57 : FreeBSD-SA-99:01:BSD File Flags and Programming Techniques
    - A user can set flags and mode on the device which they logged into. Since a bug in login and other similar programs causes the normal chown to fail, this first user will own the terminal of any login.

  • 11/4/1998 17:56 : FreeBSD-SA-98:08:IP fragmentation denial of service
    - There is a bug in the IP fragment reassembly code that might lead to a kernel panic. An attacker can create and send a pair of malformed IP packets which are then reassembled into an invalid UDP datagram. Such an UDP datagram would then cause a server to panic and crash.

  • 10/13/1998 17:56 : FreeBSD-SA-98:07:TCP RST denial of sevice
    - A denail of service attack can be launched against FreeBSD systems running without one of the patches supplied later in this message. Using a flaw in the interpreation of sequence numbers in the RST packet, malicious users can terminate connections of other users at will.

  • 6/10/1998 17:56 : FreeBSD-SA-98:06:smurf attack
    - As can be read in CERT advisory CA-98.01.smurf, there exists a denial of service attack called "smurfing". This attack sends ICMP echo requests to the broadcast address of a network. This results in the source address of the ICMP packets being flooded with ICMP echo replies. Of course, the source address is spoofed.

  • 6/4/1998 17:55 : FreeBSD-SA-98:05:system crash with NFS
    - When creating hard links on file systems, the kernel checks that both the original file and the link to it are located on the same file system. Unfortunately, there is an error in the NFS kernel code in FreeBSD 2.2.* systems that performs this check.

  • 6/2/1998 17:37 : FreeBSD-SA-98:04:security compromise via mmap
    - It is possible for a process to open an append-only file according to the limitations of the flags, and then mmap the file shared with write permission even when the file is marked as append-only or immutable. This circumvents the concept of the the append-only flag.

  • 5/14/1998 17:55 : FreeBSD-SA-98:03:Problems with TTCP
    - An accelerated open is initiated by a client by sending a new TCP option, called CC, to the server. The kernel keeps a special cache for each host it communicated with, among others containing the value of the last CC option used by the client. A new accelerated open is allowed when the CC sent is larger than the one in the per-host cache. Thus one can spoof complete connections.

  • 3/12/1998 17:54 : FreeBSD-SA-98:02:security compromise via mmap
    - Due to a 4.4BSD VM system problem, it is possible to memory-map a read-only descriptor to a character device in read-write mode.

  • 12/9/1997 17:54 : FreeBSD-SA-97:06:Pentium processors have flaw allowing unpriviledged crashes
    - A specific sequence of instructions, starting with the byte codes F0 0F (hex) cause Pentium processors to lock up. This lockup wedges the entire system, requiring a hard reset to correct. Systems that allow users to run arbitrary code are vulnerable to this attack.

  • 12/1/1997 17:54 : FreeBSD-SA-98:01:LAND attack can cause harm to running FreeBSD systems
    - A problem exists in most FreeBSD derived stacks that allows a malicious user to send a packet that causes the sytsem to lock up, thus producing a denial of service attack.

  • 10/29/1997 17:53 : FreeBSD-SA-97:05:security compromise via open()
    - A problem exists in the open() syscall that allows processes to obtain a valid file descriptor without having read or write permissions on the file being opened. This is normally not a problem. The FreeBSD way of obtaining the right to do io instructions however, is based on the right to open a specific file (/dev/io).

  • 8/19/1997 17:53 : FreeBSD-SA-97:04:security compromise via procfs
    - A problem exists in the procfs kernel code that allows processes to write memory of other processes where it should have been prohibited.

  • 4/7/1997 17:53 : FreeBSD-SA-97:03:sysinstall bug
    - One of the port installation options in sysinstall is to install an anonymous ftp setup on the system. In such a setup, an extra user needs to be created on the system, with username 'ftp'. This user is created with the shell equal to '/bin/date' and an empty password.

  • 3/26/1997 17:52 : FreeBSD-SA-97:02:Buffer overflow in lpd
    - The lpd program runs as root. A remote attacker can exploit a buffer overflow to obtain root privs.

  • 1/18/1997 17:52 : FreeBSD-SA-96:21: unauthorized access via buffer overrun in talkd
    - Buffer overrun (aka stack overflow) exploits in system supplied and locally installed utilities are commonly used by individuals wishing to obtain unauthorized access to computer systems. The FreeBSD team has been reviewing and fixing the source code pool to eliminate potential exploits based on this technique. Recently, the Australian CERT organization received information of a buffer-overrun vulnerability in the talkd daemon shipped in most modern BSD based systems.

  • 12/16/1996 17:51 : FreeBSD-SA-96:20:unauthorized access via buffer overruns cron, crontab, ppp
    - The programs in question store user-supplied information in internal buffers. There is no range checking on length of the data copied into these buffers. A malicious user may be able to overflow these buffers through the use of command line options or via enviornment variables and insert and execute their own code fragment which could be used to obtain unauthorized access to the system

  • 12/10/1996 17:51 : FreeBSD-SA-96:19:Buffer overflow in modstat
    - The modstat program has always been installed setuid kmem. Within the program, a buffer overflow can occur.

  • 11/25/1996 17:51 : FreeBSD-SA-96:18:Buffer overflow in lpr (revised)
    - Due to its nature, the lpr program is setuid root. Unfortunately, the program does not do sufficient bounds checking on arguments which are supplied by users. As a result it is possible to overwrite the internal stack space of the program while it's executing. This can allow an intruder to execute arbitrary code by crafting a carefully designed argument to lpr. As lpr runs as root this allows intruders to run arbitrary commands as root.

  • 7/16/1996 17:51 : FreeBSD-SA-96:17:
    - The Z-Modem protocol specifies a mechanism which allows the transmitter of a file to execute an arbitrary command string as part of the file transfer. This is typically used to rename files or eliminate temporary files. A malicious "trusted" sender could send down a command that could damage a user's environment.

  • 7/12/1996 17:50 : FreeBSD-SA-96:16:security vulnerability in rdist
    - rdist creates an error message based on a user provided string, without checking bounds on the buffer used. This buffer is on the stack, and can therefore be used to execute arbitrary instructions.

  • 7/4/1996 17:50 : FreeBSD-SA-96:15:security compromise from ppp
    - The ppp program does not properly manage user privileges, allowing users to run any program with root privileges.

  • 6/28/1996 17:49 : FreeBSD-SA-96:12:security compromise from perl (suidperl) utility
    - The authors of perl provide a "suidperl" program for proper processing of setuid perl scripts on systems where race conditions where setuid scripts could be exploited to gain unauthorized access. FreeBSD installs this suidperl program (and a link) as part of the standard installation. However, privilege processing done by this program does not take into account recent functionality extensions in the seteuid/setegid system calls.

  • 6/24/1996 17:49 : FreeBSD-SA-96:14:Firewall filter leak with user level ipfw
    - A potential problem exists when users specify mask addresses to ipfw(8) using the address:mask syntax. Specifically, whenever the ':' syntax is used, the resulting mask is always 0xffffffff.

  • 6/5/1996 17:49 : FreeBSD-SA-96:13:unauthorized mail reading via comsat
    - The comsat daemon does not properly set privileges before attempting to read mail files for display on a user terminal.

  • 5/22/1996 17:48 : FreeBSD-SA-96:09:unauthorized access via mount_union / mount_msdos (vfsload)
    - The mount_union and mount_msdos programs invoke another system utility in an insecure fashion while setuid root.

  • 5/22/1996 17:48 : FreeBSD-SA-96:10:system stability compromise via mount_union program
    - The union filesystem code had problems with certain mount ordering problems. By executing a certain sequence of mount_union commands, an unprivileged local user may cause a system reload. NOTE: This is a different problem than the one discussed in FreeBSD SA-96:09. The workaround for this vulnerability is similar to the one discussed in 96:09, but the proper solution for the unauthorized access problem in 96:09 does not address this vulnerability.

  • 5/22/1996 17:48 : FreeBSD-SA-96:11:security compromise from man page utility
    - The man program is setuid to the "man" user. By executing a particular sequence of commands, an unprivileged local user may gain the access privileges of the "man" user. However, root access could be obtained with further work.

  • 5/22/1996 0:36 : FreeBSD-SA-96:01:sliplogin unauthorized access vulnerability
    - The sliplogin program is used to allow a remote user to dial into a FreeBSD system and start a SLIP connection. The sliplogin program is typically used as replacement user "shell" in this application. The sliplogin program invokes a child process that may be compromised through the passing of certain environment variables.

  • 4/22/1996 17:47 : FreeBSD-SA-96:02:apache httpd meta-character escaping
    - Versions of the apache http daemon before release 1.05 do not properly restrict shell meta-characters transmitted to the daemon via form input (via GET or POST).

  • 4/21/1996 17:47 : FreeBSD-SA-96:08:syslog vulnerability
    - Bounds checking for syslog error messages was not being performed properly.

  • 4/20/1996 17:47 : FreeBSD-SA-96:03:*suggested action only* sendmail smrsh now available
    - Sendmail has the ability to deliver mail to a program on the local system via a pipe. This feature is often used to support automatic mail filtering and vacation programs. This provides a very flexible way to deliver information to an automated task running on a mailserver. Unfortunately, this allows unprivileged users to write tasks that may not properly check for common attacks via the program delivery system. The next release of FreeBSD will now install the sendmail restricted shell utility, smrsh in /usr/libexec and create the directory /usr/libexec/sm.bin to hold programs that may be executed by sendmail to deliver mail to pipes.

  • Contact Us | Legal Notice | About Our Site
    © Guardian Digital, Inc., 2000