FreeBSD : sysutils/openzfs-kmod -- critical permissions issues (2ed7e8db-e234-11ea-9392-002590bc43be)

high Nessus Plugin ID 139739

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Andrew Walker reports : Issue 1 :

Users are always granted permissions to cd into a directory. The check for whether execute is present on directories is a de-facto no-op.
This cannot be mitigated without upgrading. Even setting an explicit 'deny - execute' NFSv4 ACE will be bypassed.

Issue 2 :

All ACEs for the owner_group (group@) and regular groups (group:<foo>) are granted the current user. This means that POSIX mode 770 is de-facto 777, and the below ACL is also de-facto 777 because the groupmember check for builtin_administrators returns True.

root@TESTBOX[~]# getfacl testfile # file: testfile # owner: root # group: wheel group:builtin_administrators:rwxpDdaARWcCos:-------:allow

Solution

Update the affected package.

See Also

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248787

http://www.nessus.org/u?a1a36c1f

https://reviews.freebsd.org/D26107

http://www.nessus.org/u?86006cf9

Plugin Details

Severity: High

ID: 139739

File Name: freebsd_pkg_2ed7e8dbe23411ea9392002590bc43be.nasl

Version: 1.1

Type: local

Published: 8/21/2020

Updated: 8/21/2020

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:openzfs-kmod, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 8/20/2020

Vulnerability Publication Date: 8/13/2020