OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
BID:27252
Info
OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
| Bugtraq ID: | 27252 |
| Class: | Design Error |
| CVE: |
CVE-2008-0384 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 11 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Chris Cappuccio discovered this issue. |
| Vulnerable: |
OpenBSD OpenBSD 4.2 OpenBSD OpenBSD -current |
| Not Vulnerable: | |
Discussion
OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
OpenBSD is prone to a local denial-of-service vulnerability when the kernel handles a specially crafted IOCTL request.
Exploiting this issue allows attackers with local, interactive access to affected computers to trigger kernel panics, which will deny further service to legitimate users.
OpenBSD 4.2 through OpenBSD-current (as of 11 January, 2008) are vulnerable to this issue. Previous versions did not have the vulnerable IOCTL code.
OpenBSD is prone to a local denial-of-service vulnerability when the kernel handles a specially crafted IOCTL request.
Exploiting this issue allows attackers with local, interactive access to affected computers to trigger kernel panics, which will deny further service to legitimate users.
OpenBSD 4.2 through OpenBSD-current (as of 11 January, 2008) are vulnerable to this issue. Previous versions did not have the vulnerable IOCTL code.
Exploit / POC
OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the reference section for more information.
OpenBSD OpenBSD 4.2
Solution:
The vendor has released fixes to address this issue. Please see the reference section for more information.
OpenBSD OpenBSD 4.2
-
OpenBSD 005_ifrtlabel.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/005_ifrtlabel.pat ch
References
OpenBSD 'rtlabel_id2name()' Local Denial of Service Vulnerability
References:
References:
- OpenBSD 4.2 Errata Page (OpenBSD)
- OpenBSD Homepage (OpenBSD)
- errata 005 for OpenBSD 4.2: local users can provoke a kernel panic (OpenBSD)