FB_security 板


-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 04/30/14 02:16, Wout Decr=E9 wrote: > On Wed, 2014-04-30 at 04:35 +0000, FreeBSD Security Advisories > wrote: >> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D >> >> = FreeBSD-SA-14:07.devfs Security Advisory >> The FreeBSD Project >> = >> Topic: devfs rules not applied by default for jails >> = >> Category: core Module: etc_rc.d Announced: >> 2014-04-30 Affects: FreeBSD 10.0 Corrected: >> 2014-04-30 04:03:05 UTC (stable/10, 10.0-STABLE) 2014-04-30 >> 04:04:42 UTC (releng/10.0, 10.0-RELEASE-p2) CVE Name: >> CVE-2014-3001 >> = >> For general information regarding FreeBSD Security Advisories, = >> including descriptions of the fields above, security branches, >> and the following sections, please visit >> <URL:http://security.FreeBSD.org/>. >> = >> I. Background >> = >> The device file system, or devfs(5), provides access to kernel's >> device namespace in the global file system namespace. >> = >> The devfs(5) rule subsystem provides a way for the administrator >> of a system to control the attributes of DEVFS nodes. Each DEVFS >> mount-point has a ``ruleset'', or a list of rules, associated >> with it, allowing the administrator to change the properties, >> including the visibility, of certain nodes. >> = >> II. Problem Description >> = >> The default devfs rulesets are not loaded on boot, even when >> jails are used. Device nodes will be created in the jail with >> their normal default access permissions, while most of them >> should be hidden and inaccessible. >> = >> III. Impact >> = >> Jailed processes can get access to restricted resources on the >> host system. For jailed processes running with superuser >> privileges this implies access to all devices on the system. >> This level of access could lead to information leakage and >> privilege escalation. >> = >> IV. Workaround >> = >> Systems that do not run jails are not affected. >> = >> The system administrator can do the following to load the default >> ruleset: >> = >> /etc/rc.d/devfs onestart >> = >> Then apply the default ruleset for jails on a devfs mount using: >> = >> devfs -m ${devfs_mountpoint} rule -s 4 applyset >> = >> Or, alternatively, the following command will apply the ruleset >> over all devfs mountpoints except the host one: >> = >> mount -t devfs | grep -v '^devfs on /dev ' | awk '{print $3;}' | >> \ xargs -n 1 -J % devfs -m % rule -s 4 applyset >> = >> After this, the system administrator should add the following >> configuration to /etc/rc.conf to make it permanent, so the above >> operations do not have to be done each time the host system >> reboots. >> = >> devfs_load_rulesets=3D"YES" > = > I have always used the following rc.conf options to start jails: > = > jail_xxx_devfs_enable=3D"YES" = > jail_xxx_devfs_ruleset=3D"devfsrules_jail" > = > If jail_xxx_devfs_enable is set to NO, would there be a problem? I = > thought you always had to set jail_xxx_devfs_ruleset when enabling > devfs on jails. > = > I think this has the same effect as the workaround above? Assuming the jail have no access to the device file system at all, you would not be affected by the problem. Setting jail_*_devfs_ruleset by itself is not sufficient because a recent change (only in 10.x) have removed the loading of default rules, making setting the rule set no-op. No, you don't have to set per-jail ruleset explicitly, the default is devfsrules_jail unless overridden. Cheers, - -- = Xin LI <[email protected]> https://www.delphij.net/ FreeBSD - The Power to Serve! Live free or die -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (FreeBSD) iQIcBAEBCgAGBQJTYUToAAoJEJW2GBstM+nsnCEP/RnPDhR+QmvOhbdRwKeuDdcn SmcDtm+LmJSCxMfkVdDEuskQiI474xfrkGe6+6iIFkjilTU3/0xdKo4eIybp3ARd osYHJg9zUINIzHh2ez9CR+IqzYS/FD1jWMShhoB/qqWJayclXyz+HdfLCcryOQDn oYwneuYBRTKLSvViBAbq0pQmfzQX9mmeoSm8rR0lHuOdAfDTNyYKrod7Gku62BHL 2WZmXlgIFVsn+F3k0Ay2eG36D0ZxoAe/gQVhA3VAjSQXsgzWXmUccwpiPqK32mba gfRVfnC+ARdW0EQxWk258Z5oaAuLWXq2ntaVyr0RjODHXZr2Wi7nDRHSxczDGCrk yMSdcvHhSOx7dJxRkTashCS+5wwf2yPHChYI7t5XgO2aXukLlOTvM/HHKs0KZiyE MP1hNjujXu3t6JcIDLcuOogn2YrRYtkprphpjn0W3fN6dOjn2cyjn2o0fRoORerW ouqaunygcdCxWHUVWJeyql5aTPUJNMPEhkE/xIHNDtwlg9SNVUopMUsHzTN++yMB QEwMH91p4YaUnllW3u4At6WishkiwObIr6Ygtz7YvJja45F8g5ftRaOUdNNWONse WHDh/e0sxV6RIGr/yr28h2NVk2Kxqu7bP6XyVIV1F/qtuXkJPYyE5x9/DERreeYw 9sXDbKH7qzj/ANF4kUsY =3Dbdkk -----END PGP SIGNATURE----- _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "[email protected]"







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草
伺服器連線錯誤,造成您的不便還請多多包涵!
「贊助商連結」






like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:WOW站內搜尋

TOP