ASA-2019-00033 – OpenBSD: The unveil() system call can leak memory


Allele Security Alert

ASA-2019-00033

Identifier(s)

ASA-2019-00033

Title

The unveil() system call can leak memory

Vendor(s)

The OpenBSD Project

Product(s)

OpenBSD

Affected version(s)

OpenBSD 6.4 before errata 013

Fixed version(s)

OpenBSD 6.4 errata 013

Proof of concept

Unknown

Description

The unveil() system call can leak memory.

Technical details

Unknown

Credits

Unknown

Reference(s)

OpenBSD 6.4 Errata
https://www.openbsd.org/errata64.html

OpenBSD 6.4 errata 013, January 27, 2019:
https://ftp.openbsd.org/pub/OpenBSD/patches/6.4/common/013_unveil.patch.sig

OpenBSD Errata: January 27th, 2019 (unveil)
https://marc.info/?l=openbsd-announce&m=154853988205699&w=2

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: January 28, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.