OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
BID:8978
Info
OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
| Bugtraq ID: | 8978 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 04 2003 12:00AM |
| Updated: | Nov 04 2003 12:00AM |
| Credit: | This vulnerability was discovered by Georgi Guninski. |
| Vulnerable: |
OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 |
| Not Vulnerable: | |
Discussion
OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
The OpenBSD team has fixed a vulnerability in the OpenBSD kernel when handling certain executables. It appears that the problem lies in the lack of specific sanity checks on binary header values. As a result, a user who constructs a malformed binary and subsequently executes it may trigger a kernel panic.
*** November 5, 2003 - New information discovered by the researcher suggests that the implications of this vulnerability could in fact be higher then initially anticipated. As such, it is believed that successful exploitation of this issue under some conditions could potentially lead to code execution within the context of the kernel. This has been conjectured due to varying crashes observed when triggering the condition. Due to the lack of details regarding this possiblity, the status of this BID will remain the same until more information is available.
The OpenBSD team has fixed a vulnerability in the OpenBSD kernel when handling certain executables. It appears that the problem lies in the lack of specific sanity checks on binary header values. As a result, a user who constructs a malformed binary and subsequently executes it may trigger a kernel panic.
*** November 5, 2003 - New information discovered by the researcher suggests that the implications of this vulnerability could in fact be higher then initially anticipated. As such, it is believed that successful exploitation of this issue under some conditions could potentially lead to code execution within the context of the kernel. This has been conjectured due to varying crashes observed when triggering the condition. Due to the lack of details regarding this possiblity, the status of this BID will remain the same until more information is available.
Exploit / POC
OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
The researcher who discovered this vulnerability has developed an exploit. An exploit (ibcs2-Exploit.c), developed by Scott Bartram, has also been made available.
The researcher who discovered this vulnerability has developed an exploit. An exploit (ibcs2-Exploit.c), developed by Scott Bartram, has also been made available.
Solution / Fix
OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
Solution:
OpenBSD has released patches to address this issue in OpenBSD 3.3 and 3.4. As such, users are advised to patch their systems as soon as possible.
OpenBSD OpenBSD 3.4
OpenBSD OpenBSD 3.3
Solution:
OpenBSD has released patches to address this issue in OpenBSD 3.3 and 3.4. As such, users are advised to patch their systems as soon as possible.
OpenBSD OpenBSD 3.4
-
OpenBSD 005_exec.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch
OpenBSD OpenBSD 3.3
-
OpenBSD 010_exec.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.3/common/010_exec.patch
References
OpenBSD Local Malformed Binary Execution Denial of Service Vulnerability
References:
References:
- OpenBSD 3.3 release errata & patch list (OpenBSD)
- OpenBSD 3.4 release errata & patch list (OpenBSD)
- OpenBSD Homepage (OpenBSD)