Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22469
HistorySep 15, 2009 - 12:00 a.m.

Re: [Full-disclosure] FreeBSD <= 6.1 kqueue() NULL pointer dereference

2009-09-1500:00:00
vulners.com
6

Przemyslaw Frasunek pisze:
> FreeBSD <= 6.1 suffers from classical check/use race condition on SMP

There is yet another kqueue related vulnerability. It affects 6.x, up to
6.4-STABLE. FreeBSD security team was notified on 29th Aug, but there is no
response until now, so I won't publish any details.

Sucessful exploitation yields local root and allows to exit from jail. For now,
you can see demo on:

http://www.vimeo.com/6554787