Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 22 Oct 1996 13:14:28 +0200
From:      Gary Howland <gary@systemics.com>
To:        Steve Reid <steve@edmweb.com>
Cc:        security@freebsd.org
Subject:   Re: [bugtraq] Serious Linux Security Bug
Message-ID:  <326CAC94.5358CBEE@systemics.com>
References:  <Pine.BSF.3.91.961021134926.189B-100000@bitbucket.edmweb.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Steve Reid wrote:
> 
> This has been discussed on the Bugtraq list for a few days now, but I
> haven't seen any talk of it here.
> 
> There is no mention of the attack working against *BSD machines except for
> one person running FreeBSD 2.1.5 who reported that his Intel EtherExpress
> card stopped working for a couple of minutes.
> 
> The attack is simple. From a Win95 box,
> ping -l 65510 buggyhost
> and it can crash or reboot some OSs. Very nasty.
> 
> Has anyone checked the FreeBSD kernel to make sure that we're not
> vulnerable?

I've tried it on 2.1 and 2.2 and they behave OK (although they don't
reply to the ping, unlike a windoze machine).

I was trying to emulate the problem with a small perl script, but
haven't got a suitable "target".  Anyone out there care to test it for
me?

Best regards,

Gary
--
pub  1024/C001D00D 1996/01/22  Gary Howland <gary@systemics.com>
Key fingerprint =  0C FB 60 61 4D 3B 24 7D  1C 89 1D BE 1F EE 09 06



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?326CAC94.5358CBEE>