Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
nvd.nist.gov
nvd.nist.gov
I remember exploiting fragmented ICMP packets on Windows 95 in like 1996 to blue-screen people using the IcEbx extension for the BitchX IRC client, I think the exploit was called sping maybe? The fact that a such a vulnerability can even exist in such fundamental code these days is mind boggling, especially when bugs in the same family were around in that stack 25+ years ago.
Between this and today's TPM exploit, I have to admit the RiiR folks are starting to have a point.
tl;dr
> An attacker could send a low-level protocol error containing a fragmented IP packet inside another ICMP packet in its header to the target machine. To trigger the vulnerable code path, an application on the target must be bound to a raw socket.
While TFA didn't mention the Patch Tuesday part, the Talos blog said the fix is included in the March release, along with some other venomous looking ones
chmod ugo-sS /bin/ping
setcap cap_net_raw+ep /bin/pingHow much harder is it to turn a typical OOB access to a stack-allocated buffer into a RCE if the stack grows up instead of down?
void outer() {
char buff[64];
read_data(buff);
process_data(buff);
}
void process_data(char* buff) {
// buffer overflow here is just as bad, even if stack grows up
}