BSDI Symmetric Multiprocessing (SMP) Vulnerability
BID:589
Info
BSDI Symmetric Multiprocessing (SMP) Vulnerability
| Bugtraq ID: | 589 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 18 1999 12:00AM |
| Updated: | Aug 18 1999 12:00AM |
| Credit: | This bug was discovered by an anonymous source and was posted to the Bugtraq mailing list by Ben Lull <[email protected]> on Tue, 17 Aug 1999. |
| Vulnerable: |
BSDI BSD/OS 4.0.1 SMP |
| Not Vulnerable: | |
Exploit / POC
BSDI Symmetric Multiprocessing (SMP) Vulnerability
In order to reproduce, run several instances of commands which will eat up large amounts of CPU (top -s .1). When the CPU hits a reasonable amount, begin to run fstat. After the first 20-30 lines your machine should stop responding.
In order to reproduce, run several instances of commands which will eat up large amounts of CPU (top -s .1). When the CPU hits a reasonable amount, begin to run fstat. After the first 20-30 lines your machine should stop responding.
Solution / Fix
BSDI Symmetric Multiprocessing (SMP) Vulnerability
Solution:
The following temporary fix has been suggested:
1. chmod 000 to /usr/bin/fstat
2. Either move or remove /etc/mp.config. During boot, if this file is not found, BSDi will not boot into SMP mode.
Please note that these fixes are not endorsed by the vendor and your mileage may vary.
Solution:
The following temporary fix has been suggested:
1. chmod 000 to /usr/bin/fstat
2. Either move or remove /etc/mp.config. During boot, if this file is not found, BSDi will not boot into SMP mode.
Please note that these fixes are not endorsed by the vendor and your mileage may vary.
References
BSDI Symmetric Multiprocessing (SMP) Vulnerability
References:
References: