From owner-freebsd-questions@FreeBSD.ORG Mon Sep 14 21:22:32 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3E920106568B for ; Mon, 14 Sep 2009 21:22:32 +0000 (UTC) (envelope-from m.seaman@infracaninophile.co.uk) Received: from smtp.infracaninophile.co.uk (gate6.infracaninophile.co.uk [IPv6:2001:8b0:151:1::1]) by mx1.freebsd.org (Postfix) with ESMTP id CC8268FC14 for ; Mon, 14 Sep 2009 21:22:31 +0000 (UTC) Received: from happy-idiot-talk.infracaninophile.co.uk (localhost [IPv6:::1]) (authenticated bits=0) by smtp.infracaninophile.co.uk (8.14.3/8.14.3) with ESMTP id n8ELMQrq051138; Mon, 14 Sep 2009 22:22:27 +0100 (BST) (envelope-from m.seaman@infracaninophile.co.uk) X-DKIM: Sendmail DKIM Filter v2.8.3 smtp.infracaninophile.co.uk n8ELMQrq051138 DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=infracaninophile.co.uk; s=200708; t=1252963347; bh=0j5T8h5g9osZAqnCra3BCqeKLau/+SYE4r2s6oFUW98=; h=Message-ID:Date:From:MIME-Version:To:CC:Subject:References: In-Reply-To:Content-Type:Cc:Content-Type:Date:From:In-Reply-To: Message-ID:Mime-Version:References:To; z=Message-ID:=20<4AAEB40B.1090302@infracaninophile.co.uk>|Date:=20M on,=2014=20Sep=202009=2022:22:19=20+0100|From:=20Matthew=20Seaman= 20|Organization:=20Infracaninophi le|User-Agent:=20Thunderbird=202.0.0.23=20(X11/20090823)|MIME-Vers ion:=201.0|To:=20dgoodin@theregister.com|CC:=20freebsd-questions@f reebsd.org|Subject:=20Re:=20reporter=20on=20deadline=20seeks=20com ment=20about=20reported=20security=20bug=0D=0A=20in=20FreeBSD|Refe rences:=20<4AAE95B2.5050409@sitpub.com>|In-Reply-To:=20<4AAE95B2.5 050409@sitpub.com>|X-Enigmail-Version:=200.95.6|Content-Type:=20mu ltipart/signed=3B=20micalg=3Dpgp-sha256=3B=0D=0A=20protocol=3D"app lication/pgp-signature"=3B=0D=0A=20boundary=3D"------------enig7FC FC45C43B92D5B005DA7B7"; b=aYlw8z5Lj5oXV2y+YDFGeqmTwWqX3Tlu5mstaxU+0OJEDUgsd8mpgeEuQtjntDC9o Taasnf4Banz+0Pt6uf8jjcUXgduFJQ/qDKR3ywvbWgd3dEvImOsk8hTVUzfSoPoOvT OwMUq+bwfn93MaYW72jHJQxIWAwVM+gWA0Sh9kHQ= X-Authentication-Warning: happy-idiot-talk.infracaninophile.co.uk: Host localhost [IPv6:::1] claimed to be happy-idiot-talk.infracaninophile.co.uk Message-ID: <4AAEB40B.1090302@infracaninophile.co.uk> Date: Mon, 14 Sep 2009 22:22:19 +0100 From: Matthew Seaman Organization: Infracaninophile User-Agent: Thunderbird 2.0.0.23 (X11/20090823) MIME-Version: 1.0 To: dgoodin@theregister.com References: <4AAE95B2.5050409@sitpub.com> In-Reply-To: <4AAE95B2.5050409@sitpub.com> X-Enigmail-Version: 0.95.6 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------enig7FCFC45C43B92D5B005DA7B7" X-Virus-Scanned: clamav-milter 0.95.2 at happy-idiot-talk.infracaninophile.co.uk X-Virus-Status: Clean X-Spam-Status: No, score=-3.0 required=5.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VERIFIED,NO_RELAYS autolearn=ham version=3.2.5 X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on happy-idiot-talk.infracaninophile.co.uk Cc: freebsd-questions@freebsd.org Subject: Re: reporter on deadline seeks comment about reported security bug in FreeBSD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 14 Sep 2009 21:22:32 -0000 This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig7FCFC45C43B92D5B005DA7B7 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Dan Goodin wrote: > Hello, >=20 > Dan Goodin, a reporter at technology news website The Register. Securit= y > researcher Przemyslaw Frasunek says versions 6.x through 6.4 of FreeBSD= > has a security bug. He says he notified the FreeBSD Foundation on Augus= t > 29 and never got a response. We'll be writing a brief article about > this. Please let me know ASAP if someone cares to comment. >=20 > Kind regards, >=20 > Dan Goodin > 415-495-5411 >=20 > -------- Original Message -------- > Subject: Re: [Full-disclosure] FreeBSD <=3D 6.1 kqueue() NULL pointer > dereference > Date: Sun, 13 Sep 2009 10:49:33 +0200 > From: Przemyslaw Frasunek > Organization: frasunek.com > To: full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com > References: <4A9028AC.9080902@freebsd.lublin.pl> >=20 > Przemyslaw Frasunek pisze: >> FreeBSD <=3D 6.1 suffers from classical check/use race condition on SM= P >=20 > There is yet another kqueue related vulnerability. It affects 6.x, up t= o > 6.4-STABLE. FreeBSD security team was notified on 29th Aug, but there i= s no > response until now, so I won't publish any details. >=20 > Sucessful exploitation yields local root and allows to exit from jail. > For now, > you can see demo on: >=20 > http://www.vimeo.com/6554787 >=20 You need to contact the Security Officer to get the official position. T= hat's security-officer@freebsd.org I don't know why you seem to think this should have been reported to the = FreeBSD Foundation. They aren't the responsible parties. What to do is clearly = explained on this web page: http://www.freebsd.org/security/security.html (which=20 Przemyslaw for one seems to have read). Cheers, Matthew --=20 Dr Matthew J Seaman MA, D.Phil. 7 Priory Courtyard Flat 3 PGP: http://www.infracaninophile.co.uk/pgpkey Ramsgate Kent, CT11 9PW --------------enig7FCFC45C43B92D5B005DA7B7 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.13 (FreeBSD) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEAREIAAYFAkqutBIACgkQ8Mjk52CukIxzewCfdC7bak2J0AAGqlQvPikfRP1q XkEAn0lFPYd3oiH9yU8Enj/utXVSdcmM =0Z3C -----END PGP SIGNATURE----- --------------enig7FCFC45C43B92D5B005DA7B7--