FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0217

This CVE name corresponds to:

Entered Topic
2012-06-27 FreeBSD -- Privilege escalation when returning from kernel

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0217
Phase Assigned(20111214)

Description

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

References

Source Reference
MLIST [xen-announce] 20120612 Xen Security Advisory 7 (CVE-2012-0217) - PV privilege escalation
MLIST [xen-devel] 20120619 Security vulnerability process, and CVE-2012-0217
CONFIRM http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/
CONFIRM http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/
CONFIRM http://smartos.org/2012/06/15/smartos-news-3/
CONFIRM http://support.citrix.com/article/CTX133161
CONFIRM http://wiki.smartos.org/display/DOC/SmartOS+Change+Log#SmartOSChangeLog-June14%2C2012
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=813428
CONFIRM https://www.illumos.org/issues/2873
CONFIRM http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
DEBIAN DSA-2508
DEBIAN DSA-2501
FREEBSD FreeBSD-SA-12:04
GENTOO GLSA-201309-24
MANDRIVA MDVSA-2013:150
MS MS12-042
NETBSD NetBSD-SA2012-003
CERT TA12-164A
CERT-VN VU#649219
OVAL oval:org.mitre.oval:def:15596
SECUNIA 55082