---------------------------------------------------------------------- Want to work within IT-Security? Secunia is expanding its team of highly skilled security experts. We will help with relocation and obtaining a work permit. Currently the following type of positions are available: http://secunia.com/hardcore_disassembler_and_reverse_engineer/ ---------------------------------------------------------------------- TITLE: FreeBSD "fruncate()" and Scheduler Local Denial of Service SECUNIA ADVISORY ID: SA22413 VERIFY ADVISORY: http://secunia.com/advisories/22413/ CRITICAL: Not critical IMPACT: DoS WHERE: Local system OPERATING SYSTEM: FreeBSD 4.x http://secunia.com/product/139/ FreeBSD 5.x http://secunia.com/product/1132/ FreeBSD 6.x http://secunia.com/product/6778/ DESCRIPTION: Some vulnerabilities have been reported in FreeBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service). 1) An error exist within the "ftruncate()" function when being used on certain file types. This can be exploited to cause a DoS by e.g. calling "ftruncate()" on a FIFO file. 2) FreeBSD permits unprivileged users to set the scheduler policy. This can be exploited to cause a DoS by e.g. setting the maximum priority for a process with large CPU usage. SOLUTION: Fixed in CVS. PROVIDED AND/OR DISCOVERED BY: Disclosed in a CVS commit by the vendor. ORIGINAL ADVISORY: http://lists.freebsd.org/pipermail/cvs-src/2006-May/063969.html http://lists.freebsd.org/pipermail/cvs-src/2006-May/064488.html ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------