Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian Wheezy DSA-3070-1: Critical FreeBSD Kernel Issues and Risks

debian
Calendar Grey November 7, 2014
Scroller Debian
A number of security flaws identified within the FreeBSD kernel may lead to service disruption or data leakage. It's advisable to perform updates.
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or information disclosure

Summary

Several vulnerabilities have been discovered in the FreeBSD kernel that
may lead to a denial of service or information disclosure.

CVE-2014-3711

Denial of service through memory leak in sandboxed namei lookups.

CVE-2014-3952

Kernel memory disclosure in sockbuf control messages.

CVE-2014-3953

Kernel memory disclosure in SCTP. This update disables SCTP, since the
userspace tools shipped in Wheezy didn't support SCTP anyway.

CVE-2014-8476

Kernel stack disclosure in setlogin() and getlogin().

For the stable distribution (wheezy), these problems have been fixed in
version 9.0-10+deb70.8.

We recommend that you upgrade your kfreebsd-9 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: kfreebsd-9
CVE ID: CVE-2014-3711 CVE-2014-3952 CVE-2014-3953 CVE-2014-8476

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.