FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
BID:20158
CVE-2006-4172 | CVE-2006-4178 |Info
FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
| Bugtraq ID: | 20158 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4178 CVE-2006-4172 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 23 2006 12:00AM |
| Updated: | Sep 26 2006 07:46PM |
| Credit: | Adriano Lima is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.4-STABLE |
| Not Vulnerable: | |
Discussion
FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
FreeBSD is prone to multiple local denial-of-service vulnerabilities. These issues occur because of input-validation flaws related to the handling of integers.
An attacker may leverage these issues to cause the affected computer to crash, denying service to legitimate users.
Versions 5.2 through 5.5 are vulnerable to these issues; other versions may also be affected.
FreeBSD is prone to multiple local denial-of-service vulnerabilities. These issues occur because of input-validation flaws related to the handling of integers.
An attacker may leverage these issues to cause the affected computer to crash, denying service to legitimate users.
Versions 5.2 through 5.5 are vulnerable to these issues; other versions may also be affected.
Exploit / POC
FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
The following exploit demonstrates one of the issues:
The following exploit demonstrates one of the issues:
Solution / Fix
FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate that these issues has been fixed in version 6.0, but Symantec has not verified this claim.
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reports indicate that these issues has been fixed in version 6.0, but Symantec has not verified this claim.
References
FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
References:
References:
- FreeBSD Homepage (FreeBSD)
- iDefense Security Advisory 09.23.06: FreeBSD i386_set_ldt Integer Signedness Vu (iDefense Labs
) - [RISE-2006002] FreeBSD 5.x kernel i386_set_ldt() integer overflow vulnerability ([email protected])
- iDefense Security Advisory 09.23.06: FreeBSD i386_set_ldt Integer Overflow Vulne (iDefense Labs
)