Chinaunix首页 | 论坛 | 博客
  • 博客访问: 382813
  • 博文数量: 105
  • 博客积分: 6010
  • 博客等级: 准将
  • 技术积分: 1145
  • 用 户 组: 普通用户
  • 注册时间: 2008-10-01 09:01
文章分类

全部博文(105)

文章存档

2010年(3)

2009年(93)

2008年(9)

我的朋友

分类: BSD

2009-04-15 09:43:17

现已发现在OpenBSD的所有活动Release版本中,pf防火墙有个安全漏洞,可能引致DoS攻击,导致内核崩溃。

目前OpenBSD开发小组已经放出了修补补丁:。

这个漏洞主要涉及到网络地址和协议的转换,临时解决办法:按IPv4和IPv6分别指定网络协议。

例:
    nat/rdr ... inet proto { tcp udp icmp } ...
    nat/rdr ... inet6 proto { tcp udp icmp6 } ...
从补丁文件的日期来看,这个漏洞从2008年8月就出现了。

下面是对这个漏洞的详细说明:

Author		 : Rembrandt
Date : 2009-04-09
Affected Software: OpenBSD Kernel
Affected OS : OpenBSD 4.{3,4,5}, OpenBSD-current
Propably older versions are affected as well
Type : Denial of Service

OSVDB :
Milw0rm :
CVE :
ISS X-Force: :
BID :
Secunia : 34676
VUPEN ID :

Trying to fix it responsible and get in contact with the vendor:

-- OpenBSD --
Contacted 2009-04-09 15:35 GMT+1
Patch avaiable 2009-04-11 23:43 UTC

We received no response nor a notification about an upcoming patch by
the developers.
-- END --

OpenBSDs PF firewall in OpenBSD 4.3 up to OpenBSD-current is prone to a
remote Denial of Service during a null pointer dereference in relation with
special crafted IP datagrams. If the firewall handles such a packet the kernel
panics.


Steps to reproduce:

If you are behind a OpenBSD firewall this nmap scan should trigger the problem
and crash your firewall device:

nmap -sO $some_host_so_that_the_firewall_handles_the_packets

For more informations please do read the patch issued by OpenBSD.


Patches and Workaround:

Patches are provided for OpenBSD 4.3, 4.4, 4.5 (upcoming, release 1st of may)
and OpenBSD-current (via CVS only) and are avaiable at the errata website.
The developers provide hints for a workaround at their errata website too.



Kind regards,
Rembrandt

阅读(675) | 评论(0) | 转发(0) |
给主人留下些什么吧!~~