Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
Insight
The following package is affected: FreeBSD
CVE-2012-0217
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products
Oracle Solaris 11 and earlier
illumos before r13724
Joyent SmartOS
before 20120614T184600Z
FreeBSD before 9.0-RELEASE-p3
NetBSD 6.0
Beta and earlier
and Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: this description clearly does not belong in CVE, because a single entry cannot be about independent codebases
however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
Severity
Classification
-
CVE CVE-2012-0217 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities