oss-sec mailing list archives
Re: sysklogd vulnerability (CVE-2014-3634)
From: Rainer Gerhards <rgerhards () hq adiscon com>
Date: Sun, 5 Oct 2014 17:01:48 +0200
2014-10-03 17:39 GMT+02:00 mancha <mancha1 () zoho com>:
On Fri, Oct 03, 2014 at 05:16:31PM +0200, Rainer Gerhards wrote:Today is Germany's national holiday. IIRC it was with 3500000000 or 350000001. I probably can't check today. I think it was on ubuntu12.04ltsfully patched. Sorry i have no better answer at the moment.In that case, Schönen Feiertag.
Danke!
Maybe when you have some time you can provide a bit more particulars. On sysklogd, I'm not seeing it. But, the flaw does exist and there is OOB access so there's no reason not to apply the fix.
I have had a pretty deep look at it. Bottom line is that I couldn't reproduce it manually either. So I checked the test environment. As it turns out, the root cause for my ability to crash was that the test scripts did not setup things properly for v3 ... some v5 binary modules kept be used. Digging deeper in the old code, a crash seems as unlikely as said in the initial report. The reason is that some masking happens, which in turn prevents most problems with the negative PRIs. I'll update the advisory soon. Sorry for the noise and thanks for keeping this straight. Rainer
Current thread:
- sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) Solar Designer (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) Rainer Gerhards (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) Rainer Gerhards (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) Rainer Gerhards (Oct 05)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 06)
- Re: sysklogd vulnerability (CVE-2014-3634) Solar Designer (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)
- Re: sysklogd vulnerability (CVE-2014-3634) mancha (Oct 03)