Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OpenBSD IBCS2 Binary Length Parameter Kernel-Based Buffer Overrun Vulnerability

A buffer overrun has been discovered within the OpenBSD kernel when handling malformed COFF executables. The problem occurs when the kernel is carrying out a read operation on the binary file, incorrectly using the length parameter within the COFF header structure without first carryout out sanity checking. As a result, a malformed binary may be capable of triggering a stack overrun within the context of kernel memory. This vulnerability could potentially be exploited to gain elevated privileges on OpenBSD 2.x-3.3 systems. It has yet to be confirmed whether this is also possible on OpenBSD 3.4, however it is said to be possible to at least trigger a kernel panic.







 

Privacy Statement
Copyright 2009, SecurityFocus