[ale] [Fwd: Test program for CVS double-free.]

Geoffrey esoteric at 3times25.net
Fri Jan 24 11:45:30 EST 2003


Of interest:

-------- Original Message --------
Subject: Test program for CVS double-free.
Date: Fri, 24 Jan 2003 10:52:41 -0500
From: Joe Testa <Joe_Testa at rapid7.com>
To: ale at ale.org
To: full-disclosure at lists.netsys.com, bugtraq at securityfocus.com


Greetings--


     Attached to this e-mail you'll find a Java program which probes a
CVS pserver for the recent double-free() vulnerability.
     I've tested it on a Linux architecture only; it would be much
appreciated if people would mail me back with its performance results
against *BSD, AIX, etc...

     Here is how this tool works:


[jdog at wonderland jdog]$ java CVSProber 192.168.1.5 jdog chad0wnzme /cvs
Connecting...connected.
Server responded with 'ok', which means that it is not vulnerable.
Probe completed.
[jdog at wonderland jdog]$ java CVSProber 192.168.1.7 anonymous /cvs
Connecting...connected.
Server killed the connection and thus appears to be vulnerable!
Probe completed.
[jdog at wonderland jdog]$


     Word.


     - Joe Testa, Rapid 7, Inc.
     http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x02B00839
     A145 B158 2CA7 00A2 BAE8  4A18 57E5 18E0 02B0 0839


(See attached file: CVSProber.tar.gz)(See attached file: 
CVSProber.tar.gz.sig)


-- 
Until later: Geoffrey		esoteric at 3times25.net

The latest, most widespread virus?  Microsoft end user agreement.
Think about it...

 CVSProber.tar.gz
 CVSProber.tar.gz.sig




More information about the Ale mailing list