FreeBSD sockargs Denial of Service and Elevation of Privilege Vulnerability (CVE-2016-1887)
FreeBSD sockargs Denial of Service and Elevation of Privilege Vulnerability (CVE-2016-1887)
Release date:
Updated on:
Affected Systems:
FreeBSD <10.3 p3
FreeBSD <10.2 p17
FreeBSD <10.1 p34
Description:
CVE (CAN) ID: CVE-2016-1887
FreeBSD is a UNIX operating system.
FreeBSD versions earlier than 10.1 p34, 10.2 p17, and 10.3 P3. the sys/kern/uipc_syscalls.c/sockargs function has an integer signature error. The local user uses the negative buflen parameter, this vulnerability can cause DoS (memory overwrite and kernel crash ).
<* Source: CTurt
The HardenedBSD team
Link: https://security.freebsd.org/advisories/FreeBSD-SA-16:19.sendmsg.asc
*>
Suggestion:
Vendor patch:
FreeBSD
-------
FreeBSD has released a Security Bulletin (FreeBSD-SA-16: 19. sendmsg) and patches for this:
FreeBSD-SA-16: 19. sendmsg: Incorrect argument handling in sendmsg (2)
Link: https://security.freebsd.org/advisories/FreeBSD-SA-16:19.sendmsg.asc
This article permanently updates the link address: