Executive Summary
Summary | |
---|---|
Title | kfreebsd-9 security update |
Informations | |||
---|---|---|---|
Name | DSA-2952 | First vendor Publication | 2014-06-05 |
Vendor | Debian | Last vendor Modification | 2014-06-05 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 7.8 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or possibly disclosure of kernel memory. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-1453 A remote, authenticated attacker could cause the NFS server become deadlocked, resulting in a denial of service. CVE-2014-3000: An attacker who can send a series of specifically crafted packets with a connection could cause a denial of service situation by causing the kernel to crash. Additionally, because the undefined on stack memory may be overwritten by other kernel threads, while difficult, it may be possible for an attacker to construct a carefully crafted attack to obtain portion of kernel memory via a connected socket. This may result in the disclosure of sensitive information such as login credentials, etc. before or even without crashing the system. CVE-2014-3880 A local attacker can trigger a kernel crash (triple fault) with potential data loss, related to the execve/fexecve system calls. Reported by Ivo De Decker. For the stable distribution (wheezy), these problems have been fixed in version 9.0-10+deb70.7. For the unstable (sid) and testing (jessie) distributions, these problems are fixed in kfreebsd-10 version 10.0-6. We recommend that you upgrade your kfreebsd-9 packages. |
Original Source
Url : http://www.debian.org/security/2014/dsa-2952 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
33 % | CWE-399 | Resource Management Errors |
33 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
33 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:24634 | |||
Oval ID: | oval:org.mitre.oval:def:24634 | ||
Title: | DSA-2952-1 kfreebsd-9 - security update | ||
Description: | Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or possibly disclosure of kernel memory. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2952-1 CVE-2014-1453 CVE-2014-3000 CVE-2014-3880 | Version: | 3 |
Platform(s): | Debian GNU/kFreeBSD 7.0 | Product(s): | kfreebsd-9 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-08-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_6a384960600711e6a6c314dae9d210b8.nasl - Type : ACT_GATHER_INFO |
2016-08-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_6d472244600711e6a6c314dae9d210b8.nasl - Type : ACT_GATHER_INFO |
2014-06-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2952.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-06-10 21:28:10 |
|
2014-06-10 13:25:37 |
|
2014-06-06 05:18:28 |
|