GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

BID:10900

Info

GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

Bugtraq ID: 10900
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Aug 09 2004 12:00AM
Updated: Aug 09 2004 12:00AM
Credit: Discovery of this vulnerability is credited to Juan Pablo Martinez Kuhn from Core Security Technologies.
Vulnerable: GNU Cfengine 2.1.7 p1
GNU Cfengine 2.1 .0a9
GNU Cfengine 2.1 .0a8
GNU Cfengine 2.1 .0a6
GNU Cfengine 2.0.7 p3
GNU Cfengine 2.0.7 p2
GNU Cfengine 2.0.7 p1
GNU Cfengine 2.0.7
GNU Cfengine 2.0.6
GNU Cfengine 2.0.5 pre2
GNU Cfengine 2.0.5 pre
GNU Cfengine 2.0.5 b1
GNU Cfengine 2.0.5
GNU Cfengine 2.0.4
GNU Cfengine 2.0.3
GNU Cfengine 2.0.2
GNU Cfengine 2.0.1
GNU Cfengine 2.0 .8p1
GNU Cfengine 2.0 .8
GNU Cfengine 2.0 .0
Not Vulnerable: GNU Cfengine 2.1.9
GNU Cfengine 2.1.8

Discussion

GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

GNU cfengine cfservd is reported prone to a remote denial of service vulnerability. The vulnerability presents itself in the cfengine cfservd AuthenticationDialogue() function that is responsible for processing SAUTH commands and also performing RSA based authentication.

The vulnerability presents itself because return values for several statements within the AuthenticationDialogue() function are not checked.

This memcpy() operation based on the return values will fail resulting in a daemon crash. A remote attacker may exploit this vulnerability to crash the affected daemon effectively denying service to legitimate users.

cfservd employs an IP based access control method (AllowConnectionsFrom). This access control must be bypassed prior to exploitation. This may hinder exploitation attempts.

This vulnerability is reported to affect versions 2.0.0 to 2.1.7p1 of cfengine cfservd.

Exploit / POC

GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

Solution:
Gentoo has released an advisory to provide updates. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-misc/cfengine-2.1.8"
emerge ">=net-misc/cfengine-2.1.8"

The vendor has released an update to address this issue:


GNU Cfengine 2.0 .0

GNU Cfengine 2.0 .8

GNU Cfengine 2.0 .8p1

GNU Cfengine 2.0.1

GNU Cfengine 2.0.2

GNU Cfengine 2.0.3

GNU Cfengine 2.0.4

GNU Cfengine 2.0.5

GNU Cfengine 2.0.5 b1

GNU Cfengine 2.0.5 pre2

GNU Cfengine 2.0.5 pre

GNU Cfengine 2.0.6

GNU Cfengine 2.0.7

GNU Cfengine 2.0.7 p1

GNU Cfengine 2.0.7 p3

GNU Cfengine 2.0.7 p2

GNU Cfengine 2.1 .0a8

GNU Cfengine 2.1 .0a9

GNU Cfengine 2.1 .0a6

GNU Cfengine 2.1.7 p1

References

GNU CFEngine AuthenticationDialogue Remote Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report