CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
BID:8699
Info
CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
| Bugtraq ID: | 8699 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2003 12:00AM |
| Updated: | Sep 25 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Nick Cleaton <[email protected]>. |
| Vulnerable: |
GNU Cfengine 2.1 .0a9 GNU Cfengine 2.1 .0a8 GNU Cfengine 2.1 .0a6 GNU Cfengine 2.0.7 p3 GNU Cfengine 2.0.7 p2 GNU Cfengine 2.0.7 p1 GNU Cfengine 2.0.7 GNU Cfengine 2.0.6 GNU Cfengine 2.0.5 pre2 GNU Cfengine 2.0.5 pre GNU Cfengine 2.0.5 b1 GNU Cfengine 2.0.5 GNU Cfengine 2.0.4 GNU Cfengine 2.0.3 GNU Cfengine 2.0.2 GNU Cfengine 2.0.1 GNU Cfengine 2.0 .0 |
| Not Vulnerable: |
GNU Cfengine 2.0 .8p1 GNU Cfengine 2.0 .8 GNU Cfengine 1.6 a11 GNU Cfengine 1.6 a10 GNU Cfengine 1.5.3 -4 |
Discussion
CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
cfengine is prone to a stack-based buffer overrun vulnerability. This issue may be exploited by remote attackers who can send malicious transaction packets to cfservd. This issue is due to insufficient bounds checking of data that is read in during a transaction with a remote user.
The vulnerability may be exploited to execute arbitrary code with the privileges of cfservd. A denial of service may also be the result of exploitation attempts as cfservd is multi-threaded and may not be configured to restart itself via a super-server such as inetd.
cfengine is prone to a stack-based buffer overrun vulnerability. This issue may be exploited by remote attackers who can send malicious transaction packets to cfservd. This issue is due to insufficient bounds checking of data that is read in during a transaction with a remote user.
The vulnerability may be exploited to execute arbitrary code with the privileges of cfservd. A denial of service may also be the result of exploitation attempts as cfservd is multi-threaded and may not be configured to restart itself via a super-server such as inetd.
Exploit / POC
CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
An exploit has been made available by kokanin.
A second exploit has been released by jsk.
A third exploit has been made available by snooq.
An exploit has been made available by kokanin.
A second exploit has been released by jsk.
A third exploit has been made available by snooq.
Solution / Fix
CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
Solution:
This issue has been addressed in cfengine versions 2.0.8/2.0.8p1. A patch has also been made available for version 2.0.7p3. Versions prior to 2.0.0 do not include the vulnerable code, but users are advised against downgrading to cfengine 1.x since these versions are no longer maintained.
Fixed versions will report exploitation attempts with the following log message:
"Bad transaction packet -- too long"
Gentoo has released an advisory (200310-02) and fixes for this issue. To obtain fixes, execute the folloiwng commands:
emerge sync
emerge -p cfengine
emerge cfengine
emerge clean
GNU Cfengine 2.0 .0
GNU Cfengine 2.0.1
GNU Cfengine 2.0.2
GNU Cfengine 2.0.3
GNU Cfengine 2.0.4
GNU Cfengine 2.0.5
GNU Cfengine 2.0.5 b1
GNU Cfengine 2.0.5 pre2
GNU Cfengine 2.0.5 pre
GNU Cfengine 2.0.6
GNU Cfengine 2.0.7
GNU Cfengine 2.0.7 p1
GNU Cfengine 2.0.7 p3
GNU Cfengine 2.0.7 p2
GNU Cfengine 2.1 .0a8
GNU Cfengine 2.1 .0a9
GNU Cfengine 2.1 .0a6
Solution:
This issue has been addressed in cfengine versions 2.0.8/2.0.8p1. A patch has also been made available for version 2.0.7p3. Versions prior to 2.0.0 do not include the vulnerable code, but users are advised against downgrading to cfengine 1.x since these versions are no longer maintained.
Fixed versions will report exploitation attempts with the following log message:
"Bad transaction packet -- too long"
Gentoo has released an advisory (200310-02) and fixes for this issue. To obtain fixes, execute the folloiwng commands:
emerge sync
emerge -p cfengine
emerge cfengine
emerge clean
GNU Cfengine 2.0 .0
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.1
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.2
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.3
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.4
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.5
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.5 b1
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.5 pre2
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.5 pre
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.6
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.7
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.7 p1
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.7 p3
-
GNU net.c.patch
http://www.securityfocus.com/data/vulnerabilities/patches/net.c.patch -
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.0.7 p2
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.1 .0a8
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.1 .0a9
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
GNU Cfengine 2.1 .0a6
-
GNU cfengine-2.0.8p1.tar.gz
ftp://ftp.iu.hio.no/pub/cfengine/cfengine-2.0.8p1.tar.gz
References
CFEngine CFServD Transaction Packet Buffer Overrun Vulnerability
References:
References:
- cfengine Homepage (GNU)
- Cfengine2 cfservd remote stack overflow (Nick Cleaton
) - Re: cfengine2-2.0.3 remote exploit for redhat (Stephen Smoogen
) - Re: cfengine2-2.0.3 remote exploit for redhat (Keith Matthews
)