SB2017101066 - Permissions, Privileges, and Access Controls in FreeBSD
Published: October 10, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-5675)
The vulnerability allows a local authenticated user to execute arbitrary code.
The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).
Remediation
Install update from vendor's website.
References
- http://packetstormsecurity.com/files/133335/FreeBSD-Security-Advisory-IRET-Handler-Privilege-Escalation.html
- http://www.securityfocus.com/archive/1/536321/100/0/threaded
- http://www.securityfocus.com/bid/76485
- http://www.securitytracker.com/id/1033376
- https://www.freebsd.org/security/advisories/FreeBSD-SA-15:21.amd64.asc