Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
BID:50541
CVE-2011-3336 |Info
Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
| Bugtraq ID: | 50541 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-3336 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 04 2011 12:00AM |
| Updated: | Mar 17 2014 11:35AM |
| Credit: | Maksymilian Arciemowicz |
| Vulnerable: |
PHP PHP 5.3.9 PHP PHP 5.3.8 PHP PHP 5.3.7 PHP PHP 5.3.6 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.3.5 PHP PHP 5.3.4 RC1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.3.10 NetBSD NetBSD 5.1 FreeBSD Freebsd 8.2 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple Mac OS X 10.6 |
| Not Vulnerable: | |
Discussion
Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
Multiple Vendors' libc library is prone to a denial-of-service vulnerability due to stack exhaustion.
Successful exploits will allow attackers to make the applications that use the affected library, unresponsive, denying service to legitimate users.
The libc library of the following platforms are affected:
NetBSD 5.1
OpenBSD 5.0
FreeBSD 8.2
Apple Mac OSX
Other versions may also be affected.
Multiple Vendors' libc library is prone to a denial-of-service vulnerability due to stack exhaustion.
Successful exploits will allow attackers to make the applications that use the affected library, unresponsive, denying service to legitimate users.
The libc library of the following platforms are affected:
NetBSD 5.1
OpenBSD 5.0
FreeBSD 8.2
Apple Mac OSX
Other versions may also be affected.
Exploit / POC
Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
Exploit codes and example inputs are available. Please see the references.
The following exploit is available:
Exploit codes and example inputs are available. Please see the references.
The following exploit is available:
Solution / Fix
Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
Solution:
Fixes for NetBSD platform is available. Please see the references for more information.
Solution:
Fixes for NetBSD platform is available. Please see the references for more information.
References
Multiple Vendors libc 'regcomp()' Stack Exhaustion Denial Of Service Vulnerability
References:
References:
- Multiple BSD libc/regcomp(3) Multiple Vulnerabilities (Maksymilian Arciemowicz)
- PHP 5.4/5.3 deprecated eregi() memory_limit bypass (Maksymilian Arciemowicz)
- Multiple BSD libc/regcomp(3) Multiple Vulnerabilities (Maksymilian Arciemowicz)