Apple Airport Extreme driver fails to handle certain beacon frames, leading to an out of bounds memory access, resulting in a so-called kernel panic. Other security implications may exist, although this hasn't been verified and no details can be provided until further research is done. This issue is being coordinated with Apple, and under common agreement it's been decided to keep the details private until a fix has been made available to end-users.
Showing posts with label memory corruption. Show all posts
Showing posts with label memory corruption. Show all posts
Thursday, November 30, 2006
MOKB-30-11-2006: Apple Airport Extreme Beacon Frame Denial of Service
Tuesday, November 28, 2006
MOKB-28-11-2006: Mac OS X shared_region_make_private_np() Memory Corruption
Mac OS X shared_region_make_private_np() system call fails to handle crafted user input, leading to an exploitable memory corruption condition. Unprivileged local users can abuse this issue in order to escalate privileges (via arbitrary code execution) or cause a denial of service.
- More details and debugging information
- Proof of concept: MOKB-28-11-2006.c
Monday, November 27, 2006
MOKB-27-11-2006: Mac OS X AppleTalk AIOCREGLOCALZN Ioctl Memory Corruption
Mac OS X AppleTalk protocol handling code is vulnerable to an exploitable memory corruption issue. This particular vulnerability is caused by failure to validate input data in the AIOCREGLOCALZN ioctl command.
- More details and debug information
- Proof of concept: MOKB-27-11-2006.c (x86)
Sunday, November 26, 2006
MOKB-26-11-2006: Mac OS X Universal Binary Loading Memory Corruption
Mac OS X fails to properly handle corrupted Universal Binaries, leading to an exploitable memory corruption condition with potential risk of kernel-mode arbitrary code execution. This particular vulnerability is caused by an integer overflow in the fatfile_getarch2() function. Local unprivileged users can abuse this issue with specially crafted Mach-O 'Universal' binaries.
- More details and debugging information
- Proof of concept: MOKB-26-11-2006.bz2
Saturday, November 25, 2006
MOKB-25-11-2006: Linux 2.6.x ReiserFS Sync Memory Corruption
The ReiserFS support code of Linux 2.6.x fails to properly handle crafted data structures, leading to an exploitable memory corruption condition when a sync is being done in a corrupted ReiserFS filesystem.
- More details
- Proof of concept: MOKB-25-11-2006.img.bz2
Thursday, November 23, 2006
MOKB-23-11-2006: Mac OS X Mach-O Binary Loading Memory Corruption
Mac OS X fails to properly handle corrupted Mach-O binaries, leading to an exploitable memory corruption condition. This is triggered by execution of a Mach-O binary with a valid mach_header structure and corrupted load_command data structures. Local unprivileged users can abuse this issue.
- More details and debug information
- Proof of concept: MOKB-23-11-2006.bz2
Saturday, November 18, 2006
MOKB-18-11-2006: NetGear MA521 Wireless Driver Long Rates Overflow
The NetGear MA521 wireless adapter (PCMCIA) ships with a version of MA521nd5.SYS that is vulnerable to a memory corruption condition. This issue may lead to arbitrary kernel-mode code execution.
- More details and debugging information
- Proof of concept: netgear_ma521_rates.rb
Wednesday, November 08, 2006
MOKB-08-11-2006: FreeBSD 6.1 UFS filesystem ffs_rdextattr() integer overflow
The UFS filesystem handling code of the FreeBSD 6.1 kernel fails to properly handle corrupted data structures, leading to exploitable memory corruption (DoS) issues and possible arbitrary code execution. This particular vulnerability is caused by an integer overflow, similar to MOKB-03-11-2006.
Tuesday, November 07, 2006
MOKB-07-11-2006: Linux 2.6.x zlib_inflate memory corruption
Linux 2.6.x zlib_inflate function can be abused by filesystems that depend on zlib compression, such as cramfs. A failure to handle crafted data, result of a read operation in a corrupted filesystem stream, may lead to memory corruption. This particular vulnerability requires a filesystem (proof of concept for cramfs provided) to fail validation (ex. no integrity checking) of the binary stream in order to reach execution of zlib_inflate()
- More details and debug information
- Proof of concept: MOKB-07-11-2006.img.bz2
Monday, November 06, 2006
MOKB-06-11-2006: Microsoft Windows kernel GDI local privilege escalation
A vulnerability in the handling of GDI kernel structures of Microsoft Windows leads to an exploitable memory corruption condition, causing a denial of service (so-called BSoD) or arbitrary code execution on successful exploitation. This would allow a local user to escalate privileges, gaining full control of the system.
- More details and debug information
- Proof of concept: GDIKernelPoC.cpp
Saturday, November 04, 2006
MOKB-04-11-2006: Solaris 10 UFS filesystem alloccgblk denial of service
The UFS filesystem handling code of the Solaris 10 kernel fails to properly handle corrupted data structures, leading to an exploitable denial of service issue and potential loss of data or corruption of the local UFS filesystems, due to memory corruption.
- More details and debug information
- Proof of concept: MOKB-04-11-2006.img.gz
Friday, November 03, 2006
MOKB-03-11-2006: FreeBSD 6.1 UFS filesystem ffs_mountfs() integer overflow
The UFS filesystem handling code of the FreeBSD 6.1 kernel fails to properly handle corrupted data structures, leading to exploitable memory corruption (DoS) issues and possible arbitrary code execution. This particular vulnerability is caused by an integer overflow at ffs_mountfs() function.
More details:
More details:
Wednesday, November 01, 2006
MoKB starts: MOKB-01-11-2006 - Apple Airport 802.11 Probe Response Kernel Memory Corruption
The Month of Kernel Bugs has started. The first bug is a memory corruption vulnerability found and contributed by fellow H D Moore.
With all the hype and buzz about the now infamous Apple wireless device driver bugs (brought to attention at Black Hat, by Johnny Cache and David Maynor, covered up and FUD'ed by others), hopefully this will bring some light (better said, proof) about the existence of such flaws in the Airport device drivers.
The vulnerability details and proof of concept code can be found in the MOKB-01-11-2006 page.
The Apple Airport driver provided with Orinoco-based Airport cards (1999-2003 PowerBooks, iMacs) is vulnerable to a remote memory corruption flaw. When the driver is placed into active scanning mode, a malformed probe response frame can be used to corrupt internal kernel structures, leading to arbitrary code execution.
With all the hype and buzz about the now infamous Apple wireless device driver bugs (brought to attention at Black Hat, by Johnny Cache and David Maynor, covered up and FUD'ed by others), hopefully this will bring some light (better said, proof) about the existence of such flaws in the Airport device drivers.
The vulnerability details and proof of concept code can be found in the MOKB-01-11-2006 page.
Trick or treat? Happy Halloween.
Subscribe to:
Posts (Atom)