Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- From: Colin Percival <cperciva@xxxxxxxxxxx>
- Date: Wed, 06 Dec 2006 02:07:16 -0800
FreeBSD Security Advisories wrote:
FreeBSD-SA-06:25.kmem Security Advisory
The FreeBSD Project
...
III. Impact
A user in the "operator" group can read the contents of kernel memory.
Such memory might contain sensitive information, such as portions of
the file cache or terminal buffers. This information might be directly
useful, or it might be leveraged to obtain elevated privileges in some
way; for example, a terminal buffer might include a user-entered
password.
For what it's worth, there was a lot of debate about whether this deserved
an advisory: Members of the operator group are allowed (by default, at least)
to read raw disk devices, so being able to read kernel memory really isn't
very much of a privilege escalation. In the end I decided to go ahead with
this advisory largely because we were already planning on issuing an advisory
this week (for a far more serious issue in GNU tar), but if a similar issue
arises next month, we might decide not to bother with an advisory.
I'd be interested to hear opinions from the FreeBSD community about whether
this sort of issue is one which anyone really cares about.
Colin Percival
FreeBSD Security Officer
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- From: Dan Lukes
- Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- From: Pawel Jakub Dawidek
- Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- From: Bill Moran
- Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- From: Josh Paetzel
- Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- Prev by Date: FreeBSD Security Advisory FreeBSD-SA-06:26.gtar
- Next by Date: Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- Previous by thread: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- Next by thread: Re: FreeBSD Security Advisory FreeBSD-SA-06:25.kmem
- Index(es):