FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
BID:5493
Info
FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
| Bugtraq ID: | 5493 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0973 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery credited to Silvio Cesare <[email protected]>. |
| Vulnerable: |
FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 |
| Not Vulnerable: |
FreeBSD FreeBSD 4.6 -STABLE |
Discussion
FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
A vulnerability has been reported for the FreeBSD system. Reportedly, a few system calls are vulnerable to signed integer buffer overflow conditions.
The vulnerability is the result of system calls assuming that some arguments were given as positive integers while, in actuality, the arguments were handled as signed integers. If a negative value was supplied for the argument, the boundary checking code would fail.
A vulnerability has been reported for the FreeBSD system. Reportedly, a few system calls are vulnerable to signed integer buffer overflow conditions.
The vulnerability is the result of system calls assuming that some arguments were given as positive integers while, in actuality, the arguments were handled as signed integers. If a negative value was supplied for the argument, the boundary checking code would fail.
Exploit / POC
FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
Solution:
FreeBSD users are advised to apply the following patch or to upgrade to 4.6.2-RELEASE or 4.6-STABLE; or to any of the RELENG_4_6 (4.6.1-RELEASE-p11), RELENG_4_5 (4.5-RELEASE-p19), or RELENG_4_4 (4.4-RELEASE-p26) security branches
dated after the respective correction dates:
2002-08-13 02:42:32 UTC (RELENG_4)
2002-08-13 12:12:36 UTC (RELENG_4_6)
2002-08-13 12:13:05 UTC (RELENG_4_5)
2002-08-13 12:13:49 UTC (RELENG_4_4)
The following patch is available:
FreeBSD FreeBSD 4.0
FreeBSD FreeBSD 4.1
FreeBSD FreeBSD 4.1.1 -RELEASE
FreeBSD FreeBSD 4.1.1
FreeBSD FreeBSD 4.2 -RELEASE
FreeBSD FreeBSD 4.2
FreeBSD FreeBSD 4.3
FreeBSD FreeBSD 4.3 -RELEASE
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.5 -RELEASE
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.6 -RELEASE
Solution:
FreeBSD users are advised to apply the following patch or to upgrade to 4.6.2-RELEASE or 4.6-STABLE; or to any of the RELENG_4_6 (4.6.1-RELEASE-p11), RELENG_4_5 (4.5-RELEASE-p19), or RELENG_4_4 (4.4-RELEASE-p26) security branches
dated after the respective correction dates:
2002-08-13 02:42:32 UTC (RELENG_4)
2002-08-13 12:12:36 UTC (RELENG_4_6)
2002-08-13 12:13:05 UTC (RELENG_4_5)
2002-08-13 12:13:49 UTC (RELENG_4_4)
The following patch is available:
FreeBSD FreeBSD 4.0
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.1
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.1.1 -RELEASE
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.1.1
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.2 -RELEASE
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.2
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.3
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.3 -RELEASE
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.4
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.5
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.5 -RELEASE
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.6
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
FreeBSD FreeBSD 4.6 -RELEASE
-
FreeBSD signed-error.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:38/signed-error.p atch
References
FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
References:
References: