1. 자유게시판
  2. 스마트폰 질문과 답
  3. 사용자 팁/사용기
  4. 아무거나 질문답
  5. 토론의 장
  6. 방명록

  1. 자유게시판
  2. 스마트폰 질문과 답
  3. 사용자 팁/사용기
  4. 아무거나 질문답
  5. 토론의 장
  6. 방명록
    오늘: 1   어제: 1   전체: 11671956  

생일 축하해요

  • 04월21일
    id: 파란푸딩
  • 04월21일
    김정은
  • 04월21일
    박정윤
  • 04월21일
    처음처럼
  • 04월21일
    박수진
  • 04월21일
    김기홍
  • 04월21일
    햐우
  • 04월21일
    두쇠
  • 04월21일
    쟈스민
  • 04월21일
    이진오

  로그인한 사람


조회 수 39590 추천 수 0 댓글 2
?

단축키

Prev이전 문서

Next다음 문서

+ - Up Down Comment Print
?

단축키

Prev이전 문서

Next다음 문서

+ - Up Down Comment Print
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=============================================================================
FreeBSD-SA-05:08.kmem                                       Security Advisory
                                                          The FreeBSD Project

Topic:          Local kernel memory disclosure

Category:       core
Module:         sys
Announced:      2005-05-06
Credits:        Christian S.J. Peron
                Uwe Doering
Affects:        All FreeBSD releases prior to 5.4-RELEASE
Corrected:      2005-05-08 10:19:37 UTC (RELENG_5, 5.4-STABLE)
                2005-05-07 03:58:26 UTC (RELENG_5_4, 5.4-RELEASE)
                2005-05-08 10:23:52 UTC (RELENG_5_3, 5.3-RELEASE-p14)
                2005-05-08 10:26:42 UTC (RELENG_4, 4.11-STABLE)
                2005-05-08 10:29:54 UTC (RELENG_4_11, 4.11-RELEASE-p8)
                2005-05-08 10:35:56 UTC (RELENG_4_10, 4.10-RELEASE-p13)
CVE Name:       CAN-2005-1406

For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit <URL:http://www.freebsd.org/security/>.

0.   Revision History

v1.0 2005-05-06  Initial release.
v1.1 2005-05-07  Updated patch to include related issues reported by
                 Uwe Doering.

I.   Background

In many parts of the FreeBSD kernel, names (of mount points, devices, files, etc.) are manipulated as NULL-terminated strings, but are provided to applications within fixed-length buffers.

II.  Problem Description

In several places, variable-length strings were copied into fixed-length buffers without zeroing the unused portion of the buffer.

III. Impact

The previous contents of part of the fixed-length buffers will be disclosed to applications.  Such memory might contain sensitive information, such as portions of the file cache or terminal buffers.
This information might be directly useful, or it might be leveraged to obtain elevated privileges in some way.  For example, a terminal buffer might include a user-entered password.

IV.  Workaround

No workaround is available.

V.   Solution

Perform one of the following:

1) Upgrade your vulnerable system to 4-STABLE or 5-STABLE, or to the RELENG_5_3, RELENG_4_11, or RELENG_4_10 security branch dated after the correction date.

2) To patch your present system:

The following patches have been verified to apply to FreeBSD 4.10, 4.11, and 5.3 systems.

a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility.

[FreeBSD 4.x]
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:08/kmem4x.patch
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:08/kmem4x.patch.asc

[FreeBSD 5.x]
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:08/kmem5x.patch
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:08/kmem5x.patch.asc

b) Apply the patch.

# cd /usr/src
# patch < /path/to/patch

c) Recompile your kernel as described in <URL:http://www.freebsd.org/handbook/kernelconfig.html> and reboot the system.

VI.  Correction details

The following list contains the revision numbers of each file that was corrected in FreeBSD.

Branch                                                           Revision
  Path
- -------------------------------------------------------------------------
RELENG_4
  src/sys/kern/uipc_usrreq.c                                    1.54.2.11
  src/sys/kern/vfs_subr.c                                      1.249.2.32
  src/sys/net/if_mib.c                                            1.8.2.3
  src/sys/netinet/ip_divert.c                                    1.42.2.8
  src/sys/netinet/raw_ip.c                                      1.64.2.20
  src/sys/netinet/tcp_subr.c                                    1.73.2.34
  src/sys/netinet/udp_usrreq.c                                  1.64.2.20
RELENG_4_11
  src/UPDATING                                              1.72.2.91.2.9
  src/sys/conf/newvers.sh                                  1.44.2.39.2.12
  src/sys/kern/uipc_usrreq.c                                1.54.2.10.8.1
  src/sys/kern/vfs_subr.c                                  1.249.2.31.6.1
  src/sys/net/if_mib.c                                        1.8.2.2.2.1
  src/sys/netinet/ip_divert.c                                1.42.2.7.2.1
  src/sys/netinet/raw_ip.c                                  1.64.2.19.2.1
  src/sys/netinet/tcp_subr.c                                1.73.2.33.4.1
  src/sys/netinet/udp_usrreq.c                              1.64.2.19.6.1
RELENG_4_10
  src/UPDATING                                             1.73.2.90.2.14
  src/sys/conf/newvers.sh                                  1.44.2.34.2.15
  src/sys/kern/uipc_usrreq.c                                1.54.2.10.6.1
  src/sys/kern/vfs_subr.c                                  1.249.2.31.4.1
  src/sys/net/if_mib.c                                       1.8.2.1.16.2
  src/sys/netinet/ip_divert.c                                1.42.2.6.6.1
  src/sys/netinet/raw_ip.c                                  1.64.2.18.4.1
  src/sys/netinet/tcp_subr.c                                1.73.2.33.2.1
  src/sys/netinet/udp_usrreq.c                              1.64.2.19.4.1
RELENG_5
  src/sys/kern/subr_bus.c                                       1.156.2.7
  src/sys/kern/uipc_usrreq.c                                   1.138.2.14
  src/sys/kern/vfs_subr.c                                       1.522.2.5
  src/sys/net/if_mib.c                                           1.13.4.2
  src/sys/netinet/ip_divert.c                                    1.98.2.3
  src/sys/netinet/raw_ip.c                                      1.142.2.5
  src/sys/netinet/tcp_subr.c                                   1.201.2.18
  src/sys/netinet/udp_usrreq.c                                  1.162.2.8
RELENG_5_4
  src/UPDATING                                             1.342.2.24.2.9
  src/sys/kern/subr_bus.c                                   1.156.2.5.2.1
  src/sys/kern/uipc_usrreq.c                               1.138.2.13.2.1
  src/sys/kern/vfs_subr.c                                   1.522.2.4.2.1
  src/sys/net/if_mib.c                                       1.13.4.1.2.1
  src/sys/netinet/ip_divert.c                                1.98.2.2.2.1
  src/sys/netinet/raw_ip.c                                  1.142.2.4.2.1
  src/sys/netinet/tcp_subr.c                               1.201.2.15.2.1
  src/sys/netinet/udp_usrreq.c                              1.162.2.7.2.1
RELENG_5_3
  src/UPDATING                                            1.342.2.13.2.17
  src/sys/conf/newvers.sh                                  1.62.2.15.2.19
  src/sys/kern/subr_bus.c                                   1.156.2.2.2.1
  src/sys/kern/uipc_usrreq.c                                1.138.2.2.2.2
  src/sys/kern/vfs_subr.c                                   1.522.2.1.2.1
  src/sys/net/if_mib.c                                           1.13.6.1
  src/sys/netinet/ip_divert.c                                    1.98.4.1
  src/sys/netinet/raw_ip.c                                  1.142.2.2.2.1
  src/sys/netinet/tcp_subr.c                                1.201.2.1.2.2
  src/sys/netinet/udp_usrreq.c                              1.162.2.3.2.1
- -------------------------------------------------------------------------

The latest revision of this advisory is available at ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:08.kmem.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (FreeBSD)

iD8DBQFCfe9TFdaIBMps37IRAoANAJ9SvXgbD8c2Pw4akOWba95PklG1NgCeOPce
Ib7DiBQuu7LR2ZG70BP+eKQ=
=8wrv
-----END PGP SIGNATURE-----
  • ?
    khunter 2005.05.11 11:43
    이거...
    날 보라구 올린거지...?
    -_-;
  • ?
    Nest 2005.05.11 14:04
    GG

List of Articles
번호 제목 글쓴이 날짜 조회 수
공지 보이콧 재팬 Boycott Japan file id: 동글래미 2019.07.20 45478
37524 FreeBSD Security Advisory FreeBSD-SA-05:07.ldt mostech 2005.05.11 1333051
37523 "StartPDA 8월 소식입니다. " 이젠 내리시죠. 7 이영박 2008.09.07 739207
37522 제가 자주 가는 사이트가 해킹당했군요 ㅡ.ㅡ 3 NorthPole 2005.02.01 299510
37521 FreeBSD Security Advisory FreeBSD-SA-05:02.sendfile mostech 2005.04.14 282052
37520 노무현 전 대통령의 서거, 삼가 고인의 명복을 빕니다. 45 id: 동글래미 2009.05.23 231665
37519 FreeBSD Security Advisory FreeBSD-SA-05:06.iir [REVISED] mostech 2005.05.11 192062
37518 FreeBSD Security Advisory FreeBSD-SA-05:06.iir [REVISED] mostech 2005.05.11 139514
37517 FreeBSD Security Advisory FreeBSD-SA-05:07.ldt mostech 2005.05.11 138314
37516 위닉스 제습기 체험단 모집하네요. 1 file id: 인조인간1호 2008.06.11 130718
37515 FreeBSD Security Advisory FreeBSD-SA-05:02.sendfile mostech 2005.04.14 92978
37514 [공유] 나는 꼼수다 전편 공유~~ 항상 최신판 올려둡니다~ 22 file id: 동글래미 2011.11.28 80783
37513 이런 상단바 어때요? 14 file id: 동글래미 2013.10.15 76226
37512 갤럭시S2 HD LTE 루팅 성공.. 148 file id: 동글래미 2011.11.04 66204
37511 (완료) 갤럭시액티브 입양하실분 계실지요? 3 Leaper 2014.01.26 60871
37510 필요하신분 계신 가요..좋은 PS1 게임 롬 사이트.. 5 니카 2010.02.14 53714
37509 옴니아 14일쓰고 취소해주겟스... 4 id: 제라드 2008.11.20 50867
37508 외장 sata하드 케이스 추천바랍니다. 5 id: wHITE 2008.09.24 50839
37507 [Anycall] M4500용 Anycall Tweak v0.04 - 벨소리프리/슬라이드 44 file 동글래미 2006.10.28 40761
» FreeBSD Security Advisory FreeBSD-SA-05:08.kmem 2 mostech 2005.05.11 39590
37505 스피 카톡방 안내입니다. 6 id: 동글래미 2014.03.08 37323
37504 [공구] 갤럭시노트 악세서리 공구 예정 안내 16 id: 동글래미 2011.12.31 32398
37503 옵티머스LTE2 강력 추천합니다~~~ 18 id: 동글래미 2012.08.02 32277
37502 [테스트부탁] 아직 확실하진 않지만 일부 HD2 안드로이드에서 GPS가 느리게 잡히는 문제를 해결한 것 같습니다. 63 id: Celes 2011.04.18 31442
37501 아수스 비보탭 노트 8 며칠 써본 감상... (필기를 주로 하는 입장에서) 6 file id: Celes 2014.03.22 31321
37500 [부산맛집] 온천장 천일탕옆 윗길 - 대길갈비 3 file mostech 2004.10.06 28623
37499 혹시 저처럼 원노트로 필기하는 태블릿PC유저분들을 위한 선물 6 file id: Celes 2010.05.13 26972
37498 갤럭시S3 유저 손 들어보삼!!!!!!! 39 id: 동글래미 2012.08.15 26585
37497 SKT요금제 변경 시 주의사항 11 id: wHITE 2011.07.29 24107
37496 LG G2 루팅+하단소프트키 높이 조절된 화면입니다~ 16 file id: 동글래미 2013.09.01 23558
Board Pagination ‹ Prev 1 2 3 4 5 6 7 8 9 10 ... 1251 Next ›
/ 1251

나눔글꼴 설치 안내


이 PC에는 나눔글꼴이 설치되어 있지 않습니다.

이 사이트를 나눔글꼴로 보기 위해서는
나눔글꼴을 설치해야 합니다.

설치 취소

Designed by sketchbooks.co.kr / sketchbook5 board skin

Sketchbook5, 스케치북5

Sketchbook5, 스케치북5

Sketchbook5, 스케치북5

Sketchbook5, 스케치북5