Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  FREEBSD : FreeBSD 9.0
  FREEBSD : FreeBSD 8.2
  FREEBSD : FreeBSD 7.4
  FREEBSD : FreeBSD 8.1
  FREEBSD : FreeBSD 7.3
  FREEBSD : FreeBSD 8.0
  FREEBSD : FreeBSD 7.2
  FREEBSD : FreeBSD7.0
  FREEBSD : FreeBSD 6.4
  FREEBSD : FreeBSD 6.3
  FREEBSD : FreeBSD 6.2
  FREEBSD : FreeBSD 5.5
  FREEBSD : FreeBSD 7.0
  FREEBSD : FreeBSD 6.0
  FREEBSD : FreeBSD 4.11
Name:FREEBSD : FreeBSD 7.1

7!FreeBSD OPIE library off-by-one overflow
document Off-by-one overflow during authentication.
 FreeBSD zfs weak permissions
document Weak file permissions may be set during transaction replay.
7!FreeBSD privilege escalation
updated since 01.12.2009
document It's possible to bypass environment variables filtering on suid program execution.
 freebsd-update weak permissions
document Read permission is always set for updated files.
 setusercontext() privilege escalation in BSD systems
document Multiple application misbihave if different limits are set via setusercontext(), resulting in different exploitation scenarios.
7!FreeBSD multiple security vulnerabilities
updated since 07.09.2008
document mount / nmount syscall implementcation buffer overflow. amd64 CPU registers privilege escalation. DoS через ICMPv6.
 FreeBSD information leak
document Integer overflow on pipe implementation allows reading data from another process' memory.
 FreeBSD libc db functions information leak
document Uninitialized memory data can be written to database file.
7!FreeBSD / Mac OS X integer overflow
document Integer overflow in kernel space on process timers.
9!FreeBSD telnetd privilege escalation
updated since 16.02.2009
document LD_xxx environment variable are not cleared on 'login' execution, makeing it's possible to execute code witi root privileges. For remote exploitation it's required to have ability to upload the file to remote system (via FTP, Web, etc).
7!FreeBSD protosw privilege escalation
document Uninitialized bluetooth and netgraph sockets.
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server