[28608] in bugtraq

home help back first fref pref prev next nref lref last post

Test program for CVS double-free.

daemon@ATHENA.MIT.EDU (Joe Testa)
Fri Jan 24 11:39:14 2003

To: full-disclosure@lists.netsys.com, bugtraq@securityfocus.com
Message-ID: <OFE42D74F2.BDA188AB-ON85256CB8.0056FF82@hq.rapid7.com>
From: "Joe Testa" <Joe_Testa@rapid7.com>
Date: Fri, 24 Jan 2003 10:52:41 -0500
MIME-Version: 1.0
Content-type: multipart/mixed; 
	Boundary="0__=0ABBE62BDFC579128f9e8a93df938690918c0ABBE62BDFC57912"
Content-Disposition: inline

--0__=0ABBE62BDFC579128f9e8a93df938690918c0ABBE62BDFC57912
Content-type: text/plain; charset=us-ascii


Greetings--


    Attached to this e-mail you'll find a Java program which probes a
CVS pserver for the recent double-free() vulnerability.
    I've tested it on a Linux architecture only; it would be much
appreciated if people would mail me back with its performance results
against *BSD, AIX, etc...

    Here is how this tool works:


[jdog@wonderland jdog]$ java CVSProber 192.168.1.5 jdog chad0wnzme /cvs
Connecting...connected.
Server responded with 'ok', which means that it is not vulnerable.
Probe completed.
[jdog@wonderland jdog]$ java CVSProber 192.168.1.7 anonymous /cvs
Connecting...connected.
Server killed the connection and thus appears to be vulnerable!
Probe completed.
[jdog@wonderland jdog]$


    Word.


    - Joe Testa, Rapid 7, Inc.
    http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x02B00839
    A145 B158 2CA7 00A2 BAE8  4A18 57E5 18E0 02B0 0839


(See attached file: CVSProber.tar.gz)(See attached file: CVSProber.tar.gz.sig)

--0__=0ABBE62BDFC579128f9e8a93df938690918c0ABBE62BDFC57912
Content-type: application/octet-stream; 
	name="CVSProber.tar.gz"
Content-Disposition: attachment; filename="CVSProber.tar.gz"
Content-transfer-encoding: base64

H4sICEJXMT4AA0NWU1Byb2Jlci50YXIA7Rr9U9tGNr/Wf8WDycWG2MY2GIgpbQmhKb0AKR9J79JM
RkhrW7GkVXclDGnzv997u5KltZaP3EzuJjPeycRYfvu+v/Zp99+cvRb8kon2R+fKefRVVqfb6Wx2
Oo86uLY2N4zPTqfX7/c2H+GD7kav3+uubyF8r4fg0Pk67JgrlYkjAB599PjoLrj7fv9G19rqag1W
4XzsS4gFHwknhITJRIID+2/OQDJxxQQkHP9i4A/BT8B1IrhkkAjfnTAP/Ah/dZ0g8KMR4aI1FIw1
VoBHiCZkIRc3cBlwdwLJ1HdZG+AXJhCdhGTM4NKRvkt/ERgfAo+ZcBKfR4McXbe9gog0nGB/psgg
bR76Av+QLEqIQUKl2W2CpK8OAqEgdc8XHyInZPUcHa0rR/jOZaCYkCyBBslHKAhcTv3EHddhmEYu
MYIyZqjb7ko7R9NTXJX4CR2PQSpRDwoTImJugkI1od5eqzdhOvbdMaoqlUyWeSk4JDlQtVp9HiAb
Y54m+IhwCtYiTi/ZkAuTT99AF7BhMmNyXTFZRy9PUlmvcEumCxhGQKG9ugQmBBcwDJyRnCHaIEQR
RzhRtQThauLPHuSiKPsoMdBFtNVzTH3EJBMWS+i2NsBBWQSLmZMwT6PIfI5cKscBKDKKsZqMfeGt
QuKHrCwxWqjQIdHR/+BQ+TIxQP7tjBw/Qn61Z8cZGZFGEWkXcbzyo/QaGucCk4J/jV7Xb2qD5LTY
teMmK+i+h+DxqJ7AJOJTigqFf8rFpKCy+vzsRRP2Dn9vAvKu9XZxfPh7jks5YJRIxPZC8BjDBBnD
GMKPBL7/SIw7Pwkn9r2ttsvDH5RqArQ/AiqyU3TwHNnYiWMWSRICCUkGceAkqLOQ0J+PnWgilzKd
nIy1lieMxeTXoY9f0DMxFALOJ6QKZEAJ5HLyEIqjw/oVQyIeRByVgPHps8idqYXcVDmQ0qvgCXd5
AGmU+AGlDUKJaWMoeAgHpAfmBMjWmQpZtD55gOSFRacMjQyxIygLIXNad+kowCRCAe0InkZeu50Z
Gs3mouxoZXzKtCe/PL6A1+llgF6a/QpXvXZnqXCNn5wUY0sQvV85g3NSd/4TuoWkqAd4fOgNSKpS
jWxeoWNsAFao9bVOd623Ad2NQb8/6PeAagQcXMfwuKBzyq58QiYHZYcl1K/4yIL78RxYvl8RtVJV
ZOd27Xke6iOkPIG+E2KGlE3UqJToox6g/hJ0tFx/dmrrJWrr0OsNeuuD7raV2j5mkCjFeH6CuRtj
0/+k0re8m0BvnkBnfdDbtBI4RnfPczH6zp1ouwbaLuLsDvp2tIeRn/hOgOlH79Z412o1P4y5SIBM
0o5Y0j7D0sWSHeO5z9uvBda+t8JPmKj89jwdDtG5vVOGqbH682EUp8lZgqEQ3gZxcnDtsphE3qnV
Yu3MboA2LJwG/qrVaiRJ9jNlefzQ7GJMqY9diNIg2LHAlfjHsC3+vn2HKRVcml9v34eSUhZwr+Qp
5wVLNuavuI+eizm0ke9yxEi+ew8rM2lpra3B69yfMVXxeOYb2cKs3FBb2wGLRpiglnZhHZ48mX+2
oRCX3eLsBmtG2MYi2FZaCZCV5QvpjNgAlHlKBjh8/cHxPMHQKgEfYTpdhqdgYLOt5Xd5LL4nnXwQ
qJQ/omVY2bmfkYNrJ4wDCyvdZ712d3O7jWVLZyJk5X5OXMzqnWn06YjBGrLyMB6Kn+/g4UHksaOI
bkKeyrupX/tJAzY3N8u/fy55Q+YpfryXGWNXew104P3OPJRqT3KArgVglijLDk2r4lO75FPz/lN4
uSbRK5OgVcK/vLe8kz1Fj97DLhlrta6jJe+WmBuw+tX36oV/fwYWYFm7m/T6HaRdHmGhS/IoahTc
zmt59iXBBv2vms1CWFG0f6B37PMowsYXNYk1umLSIiuxaZapGoXhmtDb6HRvcYMZEeWEribDPE3D
ZGsunSGpUrJrZEy0Ryw5SZNZJm6sYL8nUjZPvprmEJ+ZChvqWSWrN6wRUFAvbcAmd6Uqh0oqDeWy
pQI+x5+PdaxR2erxk/wghdpqLzdhGVs3bKhaIffSgOloMxGRfy9h3/2Sc48YqrAvx2ni8alKROqQ
oDtHjZhiJ8O9VEU+x8/aLQyVt8w4eYBs+oRTQWHaro2a9rDNZ415FSrJbwVu41HHCSTS0kcjTG73
aCc7XXi+R+cEwZJU4GE4yo5W0zGLqCeWeLwLPGyulyw+/DADfvclivqKSv/u29P2f6EoMy3pckFH
NUwKXyK73qLLS6V+KNS2jHempZz4QaDOtNTc61RLg5aIHmEhfUjdpbVMZ0ZHyGzmcJUGESrgMsi0
UwbNas2M9cJAfKJs84USYKaPeURHFHV0rPPJbDryYO5DPHPIfMpDRTLCulcIUS081oJJCwuvOt9G
LJsHgOMKLmV2CHZwk5cqS4c3Snz6Mz/z2rDR4sOh79LhopiiqRPrQ7S0N6Sy5XIh0hhFoxoBU0eq
SVczH488WFE6GrIhyADq1KEq/3sKy3U8h78d84cjo8mDVKMH+EC6/wDKDhaXKfcNn1GLiTtuwOxI
A+xhbfdsw0B11oyK5hH2CdiMN1aMPgWGPvb/wc0c1lKSUD0qnYexfZ61DWV+y5/l00hWhLNwV9+a
lV5xBfUrSDmlg5txYplS74FsPD94eXgMexfnv8DpwW8XB2fnBiMZWN7JVX/R54zqc1t3kNM8OH5R
pTjf9gb8iskjdiJe6T+O+QPTmk7nlu1FnjiEVydvDuBfJxfVXF4y0TFXXOhZUTGSXLrDQZcbKkxL
6YD2aSUNHWxOvPZKqbja7Kv7p1vsN6ckTF1pkFROBrmilc3IU0v2Mw6tatLuZyGkOGUjP/FDJ9Hj
MzfwaZ6Noe7JcsLICbxxAt9r6QQqGR58J1mRy39QM1kJ+2NG0/kWauGYTVuIE3t39VCmIezz+KY1
pM7tIvZo8gr7Qk1gs+8tPHHpPHfExAgfv6b4xc9TV7Y8fziEI5oN4n8tmsXCKQvRbF72mVE7Y0lL
q7k1G4WrWZGoPtawvjspINSXcxbSKJMpAJfY96MWvahQD1LNrPqO7uYPfeThSJXrlireaib0VlCl
Ey3hyhNt1iM4usRsgXQP4Gc4ysKhGqpXhk7NoEFbUkhk3qY9Q9kEnqhnTPfDVNvmhhKN22Oq1BP8
/fftnfgtXbiv51n+JyS8VJYpd/rC/yRKpEaD2DZkYUNioj30S5AXuWXq2WsM/4plJTrHpOSRgMkY
zU2VTr2DwSd5EfYDP7nRsmNCvyIrlqPO6Liy6Cq9MslHRppHS/tnXXfHcG7XmXQqVAsv/JI0PGNs
p6JjFceGbtWIO3VdVNYwDfIGtfCNOf1cck4j1aIV/8Lc9NCcrTdUujlD1RmvdC4udlMnZYMaIh5m
UchMGXz2niBrY1BEChV6E9G57ji3u0um9kxUqT/KPUTpyJ+PInKonbuAlv/o9pZvgxkGqRzneitJ
pKYJ4OimA4uP6kiaJFyEKZxLHUbZrOMJMYJHfP06A9GGuCtht8taxHcmbkZAz0BnVrf0jjPAUqZS
pi4PRJbyJGOYUA13DOGVICj8rf3bZ5PG3JzkLjJzHvqllDLF3kUhG7I8APO8QivTxlkvSyeF7Jgw
oXmPim105rosuq+xI8dqah2MOKpxHKrWnd5cylUInJDlVX3O8LN8NzeVy54jrpHytRVr4CdY/rNx
4uxHd+wIiKehE797nw2t6NE76PU3aS5YOLyCgfpSHQiwQVAr3V5npwLxx3IZpL9ehfiHgaPzrArx
pAyx1bMQqZs4tqsgDQOHhdGVMsDmRhVg1cCwWQV4amDYqgI0DS67FhQtg4aFibZBwyLnWhlg28JE
x2SiW4XoGhazqLtncNmvAqybNCwm3ShDbFgA+mWAdYsmNg1BLVxuGQAWObfLAM8sYjwzlG0BGJhy
WpjYMZiwWPx7E4XForsmhMV1fzCj0MLGj2Z8WETZM4xu8ZvnhiSWON43TGoBeGEAWHRxYHJpkeNn
A4VFFS8NLi1+9YvhVxZ1H5pMWOT41WDCost/Grq0cPnKwGCR88i0qIWJY8N5Ld59Yghq4fK1ScMC
8ZshhwXg1ACwBOmZEUEWk5+bTFhQXJgQFhxvDC4sNn9rqNvi278byrTY419GxrNo+99mkFp09cHg
0iKGYwpqIXJpErEI4prOa1GnZ0JYqDATwuK+Q8OqFoWPDHVZvHdsKNyCwTdIWDB8NDBYBJ0YABYM
gREgFh5CA8Ci7chg0qJKbjieJdnEhlNYAP40TW4RQxhcWnxXGoqwmDMxuLSoMjUwWLi8MhRhITE1
5LRo6tqQwiLmjcGDxRifDB56xnRmyEWDbp2CjxCdHfz4ftYeZy/mqeH3nz6tzJizRvnpLp2INKnZ
TiK1R++icdf8K/DSfjrmajTF4eBzfuzX1yBq/+9bvQ9f2XmxnVwnX43G3fe/O93+Zje//72+vo5w
mAw7vcX97//Fqr0UjNGgV7ZaWYjtJYmjZr35PI+1QscP4IandTxrD+m+qAO/0sWf/Ma4fnUXk/NL
cGrl67V0cZdGIYK5NNf2eHoZsFZ2q9cyKVRv4rJbu36ib5Dre7mOcMd+wlyMQIbPg5sdApjSK116
fxmm7rjmxDES8tUk2x9CzHgcsAxGCRHSdXN3ol/f0WXSmAm6J+tELsvGYbJmucLLEpfO7YrF/O76
mE+1ghLOA337d4A6fEeu8tOU3m+KgAY+9P3943uva+U3sUJ9E6tmXKMpLrvU7n+Het+r0dr8m7Av
53kLzJtb93F7zzvrW19FP5zVzHvfcoFA+u9WcbW3Cad0lRq2mnAYudrVxkkSD9bW4lHcDv2kzbx0
gDV5q7sWT+Qa3YVO4x95vDtiyRPJyPt2O9ed3vNOZ3v9mY6U7kYfnnf729Db39uCTmevB8/3DrYB
Nva629DfOuhDd/ugA7QL1LZvqDQs1mIt1mIt1mIt1mIt1mIt1mIt1mIt1mIt1mIt1mIt1mIt1mIt
1mIt1je2/gM5x/KVAFAAAA==

--0__=0ABBE62BDFC579128f9e8a93df938690918c0ABBE62BDFC57912
Content-type: application/octet-stream; 
	name="CVSProber.tar.gz.sig"
Content-Disposition: attachment; filename="CVSProber.tar.gz.sig"
Content-transfer-encoding: base64

iD8DBQA+MVgjV+UY4AKwCDkRAuYIAJ9ZMDgY+u9FxBjDJlvfMgtyaJFqhQCfdrr0OuwtuXaUOLp4
kgx3O2oUirw=

--0__=0ABBE62BDFC579128f9e8a93df938690918c0ABBE62BDFC57912--


home help back first fref pref prev next nref lref last post