FreeBSD Security Update – 09 November 2023

FreeBSD systems have released a security update to address multiple vulnerabilities in FreeBSD libc and FreeBSD libcap_net.

The addressed vulnerabilities could allow the remote attacker to overflow a buffer, execute arbitrary code, and gain access to the affected system by sending a specially crafted request.

Sample of the addressed vulnerabilities:

FreeBSD buffer overflow (CVE-2023-5941):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-5941
  • CVE-2023-5978
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

FreeBSD Security Update

References