The UFS filesystem handling code of the FreeBSD 6.1 kernel fails to properly handle corrupted data structures, leading to exploitable memory corruption (DoS) issues and possible arbitrary code execution. This particular vulnerability is caused by an integer overflow, similar to MOKB-03-11-2006.
Showing posts with label ufs. Show all posts
Showing posts with label ufs. Show all posts
Wednesday, November 08, 2006
MOKB-08-11-2006: FreeBSD 6.1 UFS filesystem ffs_rdextattr() integer overflow
Saturday, November 04, 2006
MOKB-04-11-2006: Solaris 10 UFS filesystem alloccgblk denial of service
The UFS filesystem handling code of the Solaris 10 kernel fails to properly handle corrupted data structures, leading to an exploitable denial of service issue and potential loss of data or corruption of the local UFS filesystems, due to memory corruption.
- More details and debug information
- Proof of concept: MOKB-04-11-2006.img.gz
Friday, November 03, 2006
MOKB-03-11-2006: FreeBSD 6.1 UFS filesystem ffs_mountfs() integer overflow
The UFS filesystem handling code of the FreeBSD 6.1 kernel fails to properly handle corrupted data structures, leading to exploitable memory corruption (DoS) issues and possible arbitrary code execution. This particular vulnerability is caused by an integer overflow at ffs_mountfs() function.
More details:
More details:
Subscribe to:
Posts (Atom)