Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2013.1163 kfreebsd-9 security update 28 August 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: kfreebsd-9 Publisher: Debian Operating System: Debian GNU/Linux 7 Impact/Access: Root Compromise -- Remote/Unauthenticated Access Privileged Data -- Remote/Unauthenticated Unauthorised Access -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2013-5209 CVE-2013-4851 CVE-2013-3077 Reference: ESB-2013.1144 ESB-2013.1143 ESB-2013.1023 Original Bulletin: http://www.debian.org/security/2013/dsa-2743 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ---------------------------------------------------------------------- Debian Security Advisory DSA-2743-1 security@debian.org http://www.debian.org/security/ Aurelien Jarno August 27, 2013 http://www.debian.org/security/faq - - ---------------------------------------------------------------------- Package : kfreebsd-9 Vulnerability : privilege escalation/information leak Problem type : local/remote Debian-specific: no CVE Id(s) : CVE-2013-3077 CVE-2013-4851 CVE-2013-5209 Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a privilege escalation or information leak. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-3077 Clement Lecigne from the Google Security Team reported an integer overflow in computing the size of a temporary buffer in the IP multicast code, which can result in a buffer which is too small for the requested operation. An unprivileged process can read or write pages of memory which belong to the kernel. These may lead to exposure of sensitive information or allow privilege escalation. CVE-2013-4851 Rick Macklem, Christopher Key and Tim Zingelman reported that the FreeBSD kernel incorrectly uses client supplied credentials instead of the one configured in exports(5) when filling out the anonymous credential for a NFS export, when -network or -host restrictions are used at the same time. The remote client may supply privileged credentials (e.g. the root user) when accessing a file under the NFS share, which will bypass the normal access checks. CVE-2013-5209 Julian Seward and Michael Tuexen reported a kernel memory disclosure when initializing the SCTP state cookie being sent in INIT-ACK chunks, a buffer allocated from the kernel stack is not completely initialized. Fragments of kernel memory may be included in SCTP packets and transmitted over the network. For each SCTP session, there are two separate instances in which a 4-byte fragment may be transmitted. This memory might contain sensitive information, such as portions of the file cache or terminal buffers. This information might be directly useful, or it might be leveraged to obtain elevated privileges in some way. For example, a terminal buffer might include an user-entered password. For the stable distribution (wheezy), these problems has been fixed in version 9.0-10+deb70.3. We recommend that you upgrade your kfreebsd-9 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJSHEe5AAoJEL97/wQC1SS+LN8IAKs4uay4a4ZbhTaiEgOZVfmZ dgTmYDsNVbddyhMedVjW6RTCOmTVjXnHzre1UTLUrLCjED0NJ52s9lZWyWypVX9S X0zCJ4Ntclizw5nCzALMbzwL3L0sSI47Mu+QJ15ooAvyT1Rkb0SykauDE7IqvMjE oKY54VEGinVYWbpEVCSdOQpke10wwoZzuCLFqcVq2P/eiMrZjS7TvOm2AzDu+L8K R7igD7rjyJJT9RXGUcVJy+3iO0UPHRjWemxUPCXmqUCdKfchWuCNaN7Ybexeo5Aa z7+g2/43gq2x1VV5ttOvASnJKGKP5dYZzou+J1751/q903KSrbRKn+Z3+6jEh88= =8Tu7 - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUh1TNBLndAQH1ShLAQKmpg//XNVZlbK3FY36olPL/l+qzA8k69ytKOzP GKH9DB6rZtygXAk70v5NAvYstRQZSehtrUGWf2DBAeNS7vPBNor5lPeSdmzwBL3l 7pToeX3YWNvGZD0eb2rLmbKeZPu4lbQUkaM1Ee5VqZ9tKnTQCzGdSV3B6yrIlTGx Nv0sE2cxC4nVhEAyu8kc/qSTEWl2R6ZwwJMhUy/OlyEnu8ySleuNpE7SBfWJSebp mrKfmHM7iQXP+gcm0Qn8aeh+C6fhBratKVi8pBcJxAxc1SUxeYafbirH5kUyuXR0 u2iPEPXJLygcSMufD/KHfBFLoceKlJ/HYfNHO0BqO1KectN7ebhG1hj/NnhpR+mY 4UAXlF02MR+jXZedabCn85xO5wOFS2QZTF+thKU3ROGHNt5glm6m3d1P+6RYuuyP 6GmR62Rcfc1gXzu+F4TkPWqandSqRILe3UipoXFd9pXQwE8s4wAPQrODnZMWbQrV FTusJFAfF08gWT09RUtYYjvXuAnORXxgAhLbyllWq0BdX2o9uV61jVDrkMBMaYhC +c9Le0HSIk9YLgfxhsicxJn/u+o7F/wD50VkU18jxVbDeOlc1/PKQXJNROUYDkky PvHDyF7tlmJYvDTC/onlbndlEMNb9guYETA++W/dI/74WgLu/LG81cZP+ybtdmPT TF2LuMSXHXc= =V3s7 -----END PGP SIGNATURE-----