OpenBSD ‘getsockopt(2)’远程拒绝服务漏洞

漏洞起因
设计错误
 
影响系统
OpenBSD OpenBSD 2.9
OpenBSD OpenBSD 2.8
OpenBSD OpenBSD 2.7
OpenBSD OpenBSD 2.6
OpenBSD OpenBSD 2.5
OpenBSD OpenBSD 2.4
OpenBSD OpenBSD 2.3
OpenBSD OpenBSD 2.2
OpenBSD OpenBSD 2.1
OpenBSD OpenBSD 4.6
OpenBSD OpenBSD 4.5
OpenBSD OpenBSD 4.4
OpenBSD OpenBSD 4.3
OpenBSD OpenBSD 4.2
OpenBSD OpenBSD 4.1
OpenBSD OpenBSD 4.0
OpenBSD OpenBSD 3.9
OpenBSD OpenBSD 3.8
OpenBSD OpenBSD 3.7
OpenBSD OpenBSD 3.6
OpenBSD OpenBSD 3.5
OpenBSD OpenBSD 3.4
OpenBSD OpenBSD 3.3
OpenBSD OpenBSD 3.2
OpenBSD OpenBSD 3.1
OpenBSD OpenBSD 3.0
 
不受影响系统
 
危害
远程攻击者可以利用漏洞使系统崩溃。
 
攻击所需条件
攻击者必须访问OpenBSD。
 
漏洞信息
OpenBSD是一款开放源代码基于BSD的操作系统。
使用任何IP_AUTH_LEVEL, IP_ESP_TRANS_LEVEL, IP_ESP_NETWORK_LEVEL, IP_IPCOMP_LEVEL其中之一作为参数调用getsockopt(2),可导致系统崩溃,造成拒绝服务攻击。
 
测试方法
 
厂商解决方案
用户可参考如下补丁:
OpenBSD OpenBSD 3.5
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.8
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.3
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.1
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.3
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.5
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.2
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.7
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.1
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.6
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.9
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.0
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.6
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.0
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.4
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 3.4
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 4.2
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.1
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.2
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.3
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.4
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.5
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.6
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.7
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.8
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
OpenBSD OpenBSD 2.9
OpenBSD 003_getsockopt.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/003_getsockopt.patch
 
漏洞提供者
OpenBSD

发表评论?

0 条评论。

发表评论