Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 80269 - net-analyzer/fprobe: Weak Hash Functions Denial of Service
Summary: net-analyzer/fprobe: Weak Hash Functions Denial of Service
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: C3 [noglsa] lewk
Keywords:
Depends on:
Blocks:
 
Reported: 2005-01-31 16:17 UTC by Luke Macken (RETIRED)
Modified: 2005-02-03 13:47 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Luke Macken (RETIRED) gentoo-dev 2005-01-31 16:17:42 UTC
TITLE:
fprobe Weak Hash Functions Denial of Service

SECUNIA ADVISORY ID:
SA14072

VERIFY ADVISORY:
http://secunia.com/advisories/14072/

CRITICAL:
Less critical

IMPACT:
DoS

WHERE:
>From local network

SOFTWARE:
fprobe 1.x
http://secunia.com/product/3947/

DESCRIPTION:
A vulnerability has been reported in fprobe, which potentially can be
exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to weak hash implementations for the
xor8, xor16, and crc16 hash functions. This may be exploited to cause
a vulnerable service to consume a large amount of CPU resources by
sending some specially crafted data generating a large amount of hash
collisions.

SOLUTION:
Update to version 1.1.
http://sourceforge.net/project/showfiles.php?group_id=63535

PROVIDED AND/OR DISCOVERED BY:
Reported by vendor.
Comment 1 Luke Macken (RETIRED) gentoo-dev 2005-01-31 16:19:25 UTC
squinky86, please bump to version 1.1
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-02-03 02:48:05 UTC
netmon herd : squinky86 is MIA, please bump to 1.1.
Comment 3 Aaron Walker (RETIRED) gentoo-dev 2005-02-03 03:30:59 UTC
I'll get on it asap.
Comment 4 Aaron Walker (RETIRED) gentoo-dev 2005-02-03 03:48:54 UTC
1.1 stable on x86; vulnerable version removed. No other archs were previously stable.
Comment 5 Luke Macken (RETIRED) gentoo-dev 2005-02-03 06:35:32 UTC
Thanks Aaron.

Security, please vote on GLSA.  Local DoS... I vote no.
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-02-03 07:20:28 UTC
It's a remote DoS (local network) by CPU consumption, not a purely local one.
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-02-03 13:47:17 UTC
... but I vote NO too. Reopen if you disagree.