Test program for CVS double-free.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Greetings--


    Attached to this e-mail you'll find a Java program which probes a
CVS pserver for the recent double-free() vulnerability.
    I've tested it on a Linux architecture only; it would be much
appreciated if people would mail me back with its performance results
against *BSD, AIX, etc...

    Here is how this tool works:


[jdog@wonderland jdog]$ java CVSProber 192.168.1.5 jdog chad0wnzme /cvs
Connecting...connected.
Server responded with 'ok', which means that it is not vulnerable.
Probe completed.
[jdog@wonderland jdog]$ java CVSProber 192.168.1.7 anonymous /cvs
Connecting...connected.
Server killed the connection and thus appears to be vulnerable!
Probe completed.
[jdog@wonderland jdog]$


    Word.


    - Joe Testa, Rapid 7, Inc.
    http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x02B00839
    A145 B158 2CA7 00A2 BAE8  4A18 57E5 18E0 02B0 0839


(See attached file: CVSProber.tar.gz)(See attached file: CVSProber.tar.gz.sig)

Attachment: CVSProber.tar.gz
Description: Binary data

Attachment: CVSProber.tar.gz.sig
Description: Binary data


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux