FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
BID:32976
Info
FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 32976 |
| Class: | Unknown |
| CVE: |
CVE-2008-5736 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2008 12:00AM |
| Updated: | Mar 10 2011 04:07AM |
| Credit: | Christer Oberg |
| Vulnerable: |
FreeBSD FreeBSD 7.1 -PRE-RELEASE FreeBSD FreeBSD 7.0-RELEASE FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 FreeBSD FreeBSD 6.4 -RELEASE FreeBSD FreeBSD 6.3 -RELENG FreeBSD FreeBSD 6.3 |
| Not Vulnerable: | |
Discussion
FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
FreeBSD is prone to multiple local privilege-escalation vulnerabilities.
An attacker can exploit these vulnerabilities to run arbitrary code with elevated privileges.
All versions of FreeBSD are considered vulnerable.
FreeBSD is prone to multiple local privilege-escalation vulnerabilities.
An attacker can exploit these vulnerabilities to run arbitrary code with elevated privileges.
All versions of FreeBSD are considered vulnerable.
Exploit / POC
FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit codes are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit codes are available:
Solution / Fix
FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
FreeBSD FreeBSD 7.1 -PRE-RELEASE
FreeBSD FreeBSD 6.3
FreeBSD FreeBSD 6.4 -RELEASE
FreeBSD FreeBSD 7.0 -RELENG
FreeBSD FreeBSD 6.3 -RELENG
FreeBSD FreeBSD 7.0
FreeBSD FreeBSD 7.0-RELEASE
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
FreeBSD FreeBSD 7.1 -PRE-RELEASE
-
FreeBSD SA-08:13/protosw.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw.patch
FreeBSD FreeBSD 6.3
-
FreeBSD SA-08:13/protosw6x.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch
FreeBSD FreeBSD 6.4 -RELEASE
-
FreeBSD SA-08:13/protosw6x.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch
FreeBSD FreeBSD 7.0 -RELENG
-
FreeBSD SA-08:13/protosw.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw.patch
FreeBSD FreeBSD 6.3 -RELENG
-
FreeBSD SA-08:13/protosw6x.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch
FreeBSD FreeBSD 7.0
-
FreeBSD SA-08:13/protosw.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw.patch
FreeBSD FreeBSD 7.0-RELEASE
-
FreeBSD SA-08:13/protosw.patch
http://security.FreeBSD.org/patches/SA-08:13/protosw.patch
References
FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
References:
References:
- FreeBSD Homepage (FreeBSD)