OpenBSD select() Buffer Overflow Vulnerability
BID:5442
Info
OpenBSD select() Buffer Overflow Vulnerability
| Bugtraq ID: | 5442 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1420 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 12 2002 12:00AM |
| Updated: | Nov 03 2007 12:46AM |
| Credit: | Vulnerability first detailed in OpenBSD security advisory dated 2002-08-11. |
| Vulnerable: |
OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 |
| Not Vulnerable: | |
Discussion
OpenBSD select() Buffer Overflow Vulnerability
A buffer-overflow vulnerability has been reported for the 'select(2)' function. This function lets programmers examine I/O descriptors.
The size parameter for the 'select()' function is a signed integer. Reportedly, 'select()' evaluates the upper boundary checks in a signed context. As a result, an attacker can cause the kernel to overwrite arbitrary locations in memory when supplying 'select()' with certain negative values for the size parameter.
A buffer-overflow vulnerability has been reported for the 'select(2)' function. This function lets programmers examine I/O descriptors.
The size parameter for the 'select()' function is a signed integer. Reportedly, 'select()' evaluates the upper boundary checks in a signed context. As a result, an attacker can cause the kernel to overwrite arbitrary locations in memory when supplying 'select()' with certain negative values for the size parameter.
Exploit / POC
OpenBSD select() Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
OpenBSD select() Buffer Overflow Vulnerability
Solution:
Users are advised to apply the available patches or to update their systems to OpenBSD 3.0-stable or 3.1-stable dated 2002-08-11 17:00 EDT or later.
OpenBSD OpenBSD 3.0
OpenBSD OpenBSD 3.1
Solution:
Users are advised to apply the available patches or to update their systems to OpenBSD 3.0-stable or 3.1-stable dated 2002-08-11 17:00 EDT or later.
OpenBSD OpenBSD 3.0
-
OpenBSD 014_scarg.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/014_scarg.patch
OpenBSD OpenBSD 3.1
-
OpenBSD 014_scarg.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/014_scarg.patch
References
OpenBSD select() Buffer Overflow Vulnerability
References:
References:
- OpenBSD Homepage (OpenBSD)
- OpenBSD select() overflow exploit (CORE Security)