FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
BID:10596
Info
FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
| Bugtraq ID: | 10596 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0618 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 23 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Credit for the discovery of this vulnerability goes to Marceta Milos <[email protected]>. |
| Vulnerable: |
FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 4.10 -RELEASE |
| Not Vulnerable: | |
Discussion
FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
It is reported that FreeBSD running on the Alpha architecture is susceptible to a denial of service vulnerability in its execve() system call.
An attacker with local interactive user-level access on an affected machine is reportedly able to crash FreeBSD when running on the Alpha architecture, denying service to legitimate users.
FreeBSD 5.1-RELEASE/Alpha is reported vulnerable, other architectures with strict memory alignment requirements are also likely vulnerable. IA32 is reported immune. Versions other than 5.1-RELEASE are likely affected as well.
It is reported that FreeBSD running on the Alpha architecture is susceptible to a denial of service vulnerability in its execve() system call.
An attacker with local interactive user-level access on an affected machine is reportedly able to crash FreeBSD when running on the Alpha architecture, denying service to legitimate users.
FreeBSD 5.1-RELEASE/Alpha is reported vulnerable, other architectures with strict memory alignment requirements are also likely vulnerable. IA32 is reported immune. Versions other than 5.1-RELEASE are likely affected as well.
Exploit / POC
FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
An example proof-of-concept exploit was provided.
An example proof-of-concept exploit was provided.
Solution / Fix
FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FreeBSD execve() Unaligned Memory Access Denial Of Service Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- FreeBSD Security Information (FreeBSD)
- Security Advisory : FreeBSD local DoS (Marceta Milos
)