Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 2 Oct 2009 07:00:24 +0200
From:      Jacques Marneweck <jmarneweck@gmail.com>
To:        "Simon L. Nielsen" <simon@freebsd.org>
Cc:        freebsd-security@freebsd.org, d@delphij.net
Subject:   Re: FreeBSD bug grants local root access (FreeBSD 6.x)
Message-ID:  <4802d0520910012200p271a2d5awc5e69b9ab1235851@mail.gmail.com>
In-Reply-To: <20090928192256.GC2111@arthur.nitro.dk>
References:  <4AAF45B4.60307@isafeelin.org> <4AAF5999.7020501@delphij.net> <200909251248.n8PCmJPY011925@lava.sentex.ca> <20090928192256.GC2111@arthur.nitro.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi Simon,

Is there any further feedback regarding this bug?  Has anyone tested
to see if this also affects FreeBSD 5.x?

Regards
--jm

On Mon, Sep 28, 2009 at 9:22 PM, Simon L. Nielsen <simon@freebsd.org> wrote=
:
> On 2009.09.25 08:52:25 -0400, Mike Tancsa wrote:
>> At 05:08 AM 9/15/2009, Xin LI wrote:
>> >Frederique Rijsdijk wrote:
>> > > Hi,
>> > >
>> > > Any info on this subject on
>> > >
>> > > http://www.theregister.co.uk/2009/09/14/freebsd_security_bug/
>> >
>> >Currently we (secteam@) are testing the correction patch and do
>> >peer-review on the security advisory draft, the bug was found and fixed
>> >on -HEAD and 7-STABLE before 7.1-RELEASE during some stress test but wa=
s
>> >not recognized as a security vulnerability at that time. =C2=A0The expl=
oit
>> >code has to be executed locally, i.e. either by an untrusted local user=
,
>> >or be exploited in conjunction with some remote vulnerability on
>> >applications that allow the attacker to inject their own code.
>> >
>> >We can not release further details about the problem at this time,
>> >though, but I think we will likely to publish the advisory and
>> >correction patch this patch Wednesday.
>>
>> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Just wondering if there is any update =
on this issue ?
>
> It turned out more difficult to fix than expected and we (secteam)
> didn't handle that as well as we should have, but I think we are
> almost there so the advisory should be out soon - sometime this week
> at the latest.
>
> Sorry about the delay - this should have been fixed by now.
>
> --
> Simon L. Nielsen
> FreeBSD Deputy Security Officer

--=20
Jacques Marneweck
http://www.powertrip.co.za/
http://www.powertrip.co.za/blog/
http://www.ataris.co.za/

#include <std/disclaimer.h>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4802d0520910012200p271a2d5awc5e69b9ab1235851>