SB2018040415 - Multiple vulnerabilities in FreeBSD



SB2018040415 - Multiple vulnerabilities in FreeBSD

Published: April 4, 2018

Security Bulletin ID SB2018040415
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Infinite loop (CVE-ID: CVE-2018-6918)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to the length field of the option header does not count the size of the option header itself and pointer/offset mistakes in the handling of IPv4 options. A remote attacker can trigger infinite loop and cause the service to crash.

2) Integer overflow (CVE-ID: CVE-2018-6917)

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The weakness exists due to insufficient validation of user-provided font parameters. A remote attacker can trigger integer overflow and gain root privileges.

Remediation

Install update from vendor's website.