FreeBSD Multiple Security Bypass Vulnerabilities
BID:108395
CVE-2019-5597 | CVE-2019-5598 |Info
FreeBSD Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 108395 |
| Class: | Design Error |
| CVE: |
CVE-2019-5597 CVE-2019-5598 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2019 12:00AM |
| Updated: | May 14 2019 12:00AM |
| Credit: | Synacktiv |
| Vulnerable: |
FreeBSD Freebsd 12.0-RELEASE-p3 FreeBSD Freebsd 12.0-RELEASE p1 FreeBSD Freebsd 12.0 FreeBSD Freebsd 11.2-RELEASE-p9 FreeBSD Freebsd 11.2-RELEASE-p7 FreeBSD Freebsd 11.2-RELEASE-p6 FreeBSD Freebsd 11.2-RELEASE-p5 FreeBSD Freebsd 11.2-RELEASE-p2 FreeBSD Freebsd 11.2-RELEASE-p1 FreeBSD Freebsd 11.2-PRERELEASE FreeBSD Freebsd 11.2 FreeBSD Freebsd 11.0 |
| Not Vulnerable: |
FreeBSD Freebsd 12.0-STABLE FreeBSD Freebsd 11.3-PRERELEASE FreeBSD Freebsd 11.2-RELEASE-p10 |
Discussion
FreeBSD Multiple Security Bypass Vulnerabilities
FreeBSD is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
FreeBSD is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
Exploit / POC
FreeBSD Multiple Security Bypass Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FreeBSD Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
FreeBSD Multiple Security Bypass Vulnerabilities
References:
References:
- FreeBSD Homepage (FreeBSD)
- icmp-reachable (Synacktiv)
- CVE-2019-5597IPv6 fragmentation vulnerability in OpenBSD Packet Filter (Synacktiv)
- FreeBSD-SA-19:05.pf : IPv6 fragment reassembly panic in pf(4) (FreeBSD)
- FreeBSD-SA-19:06.pf: ICMP/ICMP6 packet filter bypass in pf (FreeBSD)
- Oracle Critical Patch Update Advisory - July 2019 (Oracle)