FreeBSD : FreeBSD -- vt console memory disclosure (a5cf3ecd-38db-11e8-8b7f-a4badb2f469b)

high Nessus Plugin ID 108858

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Characters that reference this data can be displayed on the screen, effectively disclosing kernel memory. Impact :
Unprivileged users may be able to access privileged kernel data.

Such memory might contain sensitive information, such as portions of the file cache or terminal buffers. This information might be directly useful, or it might be leveraged to obtain elevated privileges in some way; for example, a terminal buffer might include a user-entered password.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?2686f053

Plugin Details

Severity: High

ID: 108858

File Name: freebsd_pkg_a5cf3ecd38db11e88b7fa4badb2f469b.nasl

Version: 1.7

Type: local

Published: 4/6/2018

Updated: 12/7/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:freebsd, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Settings/ParanoidReport, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 4/5/2018

Vulnerability Publication Date: 4/4/2018

Reference Information

CVE: CVE-2018-6917

FreeBSD: SA-18:04.vt