-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2508-1 security@debian.org http://www.debian.org/security/ Yves-Alexis Perez July 22, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kfreebsd-8 Vulnerability : privilege escalation Problem type : local Debian-specific: no CVE ID : CVE-2012-0217 Debian Bug : 677297 Rafal Wojtczuk from Bromium discovered that FreeBSD wasn't handling correctly uncanonical return addresses on Intel amd64 CPUs, allowing privilege escalation to kernel for local users. For the stable distribution (squeeze), this problem has been fixed in version 8.1+dfsg-8+squeeze3. For the testing distribution (wheezy), this problem has been fixed in version 8.3-4. For the unstable distribution (sid), this problem has been fixed in version 8.3-4. We recommend that you upgrade your kfreebsd-8 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCgAGBQJQC/BGAAoJEDBVD3hx7wuoI5kQAJYu29HG2VQ4hXZoEtyVIkYh 9h/IEGcblTfKtwLFec+x79uyyCf6/mdJbjyujRlGXmMG2fA09Im4wSI34BkV44No mMp4vmM6Xwf5EX0bEoGSRn78vgMEpgEybIZ1m691u8Au1wQ2t9FqLsnWtQ5l5f9w b2k19MPGpygwBgwyeUpLXDXbytkpqg0NoQLbDmwHvWti0GvbwutkRMPSJwRH7Ifv OBWa9H85AXj7p/qZA9LtAMCeOy/s8WWDT5iILRqSvKcdJXJkuc6Qpzc3MwiiPz64 bH0lrcpWRGmMjrTdJLiCLY4Y35s4ClGGB/JN+8drMl9N3NENiLLsgYhr5gtM3Y2Q C0HnYLRHgt27QxUWKJk1B0Ale3W4H3YfqYZ9405LjbPxOmXrMuj9ZgaSBIjs2s4U VbLcZnvhWiOp6ep2KSQ5gkC6tBHKMT6y03ONqKI7oBuY6c2mGozNerGdEhh11q7G PXPZg6XEZ/qQ3K+0J3TKiJh7L8EunLdCkYdGH8RJfIdv2jGSlIv9c5XehIhucWKG oSPMZyHK2DqHh71jo/5JbVYEr9fQufhbXewNjIc6i6GQY0jRgPw09cL2gXIfip4L wbdAYORGPQNXccwgQaaNRbz4r9rvrf9GIisrdnB9f5fTmQ2lbreG5dD3AYMwemAP KcijNtCKiz52Fap9LWxX =DH+Y -----END PGP SIGNATURE-----