Staunch your Heartbleed patching: FreeBSD has a nasty credentials leak

Let's not forget that FreeBSD is in OSX, NetApp kit, Juniper boxen and even some tellies

8 Reg comments Got Tips?

Got FreeBSD? Get busy on the patch, because a problem with its TCP ordering has emerged, with both denial-of-service and data leakage as possible effects.

The issue exists in how the popular Unix-like operating system handles TCP packets received out-of-order. Packets are held in a reassembly queue until they can be re-ordered and re-assembled. However, as the advisory states:

“FreeBSD may add a reassemble queue entry on the stack into the segment list when the reassembly queue reaches its limit. The memory from the stack is undefined after the function returns. Subsequent iterations of the reassembly function will attempt to access this entry.”

Crafted packets can cause a kernel crash, the advisory states, but worse: “because the undefined on stack memory may be overwritten by other kernel threads, while extremely difficult, it may be possible for an attacker to construct a carefully crafted attack to obtain portion of kernel memory via a connected socket”.

Ty Miller, CEO of Threat Intelligence, said in an e-mail the operating system is the basis of kit from a lot of well-known names, including: OSX, PlayStation, some Panasonic TVs; and security gear from Blue Coat, Checkpoint, IronPort, Juniper, McAfee and Sophos.

The difficulty of creating an exploit means this is far less likely to cause data leak before patches start becoming available. One issue, however, is very similar to Heartbleed: because FreeBSD is behind the scenes in non-obvious places, a lot of systems may never get patched.

While sysadmins will have charge of IT systems, almost no one except the very savvy home user patches consumer kit.

It should be noted that users will probably see denial-of-service rather than data leak as the most immediate potential impact. “Because of the complexity associated with the exploitation process, it is more likely to trigger the target system to crash,” Miller's e-mail noted.

Patch instructions are given at the FreeBSD advisory. ®

SUBSCRIBE TO OUR WEEKLY TECH NEWSLETTER


Keep Reading

Linux Foundation rolls bunch of overlapping groups into one to tackle growing number of open-source security vulns

OpenSSF to take projects from CII and OSSC under its umbrella

Nine in ten biz applications harbor out-of-date, unsupported, insecure open-source code, study shows

Free-as-in-speech software is wildly popular – keeping libraries, components up to date is not

When one open-source package riddled with vulns pulls in dozens of others, what's a dev to do?

Snyk survey puts cross-site scripting top of the list for security holes – but watch out for prototype pollution too

Open-source bug bonanza: Vulnerabilities up almost 50 per cent thanks to people actually looking for them

Can't fix flaws if you don't look for them

Maker of SonarQube defends DevOps product's security after source code leaks blamed on bad configurations

'Most companies' want to make code 'completely transparent' SonarSource claims – but not outside the firewall

Citrix tells everyone not to worry too much about its latest security patches. NSA's former top hacker disagrees

Eleven flaws cleaned up including one that may be exploited to sling malware downloads

The great big open-source census: Most-used libraries revealed – plus 10 things developers should be doing to keep their code secure

Linux Foundation hears your gripes about naming schemes, legacy code, and more

Homeland Security demands a 911 for reporting security holes in federal networks: 'Vulns in internet systems cause real-world impacts'

Great – and who will be the first responders?

Biting the hand that feeds IT © 1998–2020