what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

macosx-preauth.txt

macosx-preauth.txt
Posted Dec 1, 2006
Authored by Mu Security Research | Site labs.musecurity.com

The network kernel extension com.apple.nke.pppoe that works concurrently with the pppd has a critical vulnerability that may lead to arbitrary code execution with system privileges. Affected product and versions include Mac OS X version 10.3.9, Mac OS X Server version 10.3.9, Mac OS X version 10.4.8, and Mac OS X Server version 10.4.8.

tags | advisory, arbitrary, kernel, code execution
systems | apple, osx
SHA-256 | b5c605ccfbd217e21201254fd3af5f2ca285de19b1cb80c628719aa0964bce13

macosx-preauth.txt

Change Mirror Download
driver

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Pre-Authentication Vulnerability in Mac OSX kernel PPP driver [MU-200611-01]
November 28, 2006

http://labs.musecurity.com/advisories.html

Affected Product/Versions:

Mac OS X v10.3.9
Mac OS X Server v10.3.9
Mac OS X v10.4.8
Mac OS X Server v10.4.8

Product Overview:

"PPP is the protocol used for establishing internet links over dial-up
modems, DSL connections, and many other types of point-to-point links.
The pppd daemon works together with the kernel PPP driver to establish
and maintain a PPP link with another system (called the peer) and to
negotiate Internet Protocol (IP) addresses for each end of the link.
Pppd can also authenticate the peer and/or supply authentication infor-
mation to the peer. PPP can be used with other network protocols
besides IP, but such use is becoming increasingly rare."

Vulnerability Details:

The network kernel extension com.apple.nke.pppoe that works concurrently with
the pppd has a critical vulnerability that may lead to arbitrary code
execution with system privileges. The vulnerability is triggered by sending a
malformed PADI packet with invalid lengths to the ppp daemon. PADI is the
first message in a PPPoE link establishment and requires no credentials. In
addition, the MAC address of the sender can be spoofed. Users of PPP who do
not create PPPoE connections are not at risk of attack. PPPoE is also not
enabled by default.

Vendor Response / Solution:

All users of PPPoE on OS X are recommended to immediately apply the security
updates available from the following URL:

http://docs.info.apple.com/article.html?artnum=304829

Mu Security would like to thank Apple for timely remediation of these
vulnerabilities.

History:

09/14/06 - First contact with the vendor
11/01/06 - Fix available for the vulnerabilities
11/28/06 - Advisory released

Credit:

This vulnerability was discovered by the Mu Security research team.

http://labs.musecurity.com/pgpkey.txt

Mu Security offers a new class of security analysis system, delivering a
rigorous and streamlined methodology for verifying the robustness and security
readiness of any IP-based product or application. Founded by the pioneers of
intrusion detection and prevention technology, Mu Security is backed by
preeminent venture capital firms that include Accel Partners, Benchmark
Capital and DAG Ventures. The company is headquartered in Sunnyvale, CA. For
more information, visit the company's website at http://www.musecurity.com.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (Darwin)

iD8DBQFFbK47Ml+docYeP+YRAtYvAJsE0DymOrYWyPL363FyDIen2/B6qgCgk/uU
myV3rI7qnCMdLbJCUjqdPsk=
=Kv1p
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close