Re: Have real exploits of arithmetic overflows happened?



clc5q@xxxxxxxxxxxxxxxxxxxxx (Clark L. Coleman) (07-02-13 17:45:07):

Searching through security bulletins, you see many reports of buffer
overflow vulnerabilities, perhaps 10-15% that many format string
vulnerabilities, even fewer integer overflow and/or signedness
vulnerabilities, and even fewer double-free vulnerabilities.

These are all reported by security firms that were reviewing code, or
random open source code reviewers. What I am wondering is: Have there
actually been successful exploits of the more exotic vulnerabilities
(e.g. integer overflow or double-free), as opposed to just reports of
vulnerabilities?

In both my teaching and research I would like to comment on whether
anyone's system has ever really been damaged by an attacker using such
an exploit, as opposed to proof-of-concept reports.

Probably a lot of them have been exploited actively, but not necessarily
against large networks or well-known hosts (Google, Amazon, Ebay, ...).

I can't imagine that the TCP options bug in the Linux Netfilter wasn't
exploited somewhere in the wild. It was a signedness bug, which could
be exploited to drop the kernel into an endless loop.


Regards,
E.S.
.



Relevant Pages

  • Inaccurate Reports Concerning PHP Vulnerabilities
    ... There have been a number of reports circulating about possible ... vulnerabilities in PHP. ... gain control of the PHP interpreter, nor is it an integer overflow of any ...
    (Bugtraq)
  • RE: Top 10 vulnerabilities and open ports.
    ... Top 10 vulnerabilities and open ports. ... ports reports based on the results of the free security scans performed ... Reports are based on the results of tests performed using Nessus ...
    (Pen-Test)
  • Top 10 vulnerabilities and open ports.
    ... Inprotect.com made available top 10 vulnerabilities and top 10 open tcp ... ports reports based on the results of the free security scans performed ... Reports are based on the results of tests performed using Nessus ...
    (Pen-Test)
  • CERT Summary CS-2003-03
    ... CERT Summary CS-2003-03 ... we have seen a large volume of reports related to a mass ... on the exploitation of vulnerabilities in Microsoft's RPC ... CERT/CC, please visit the CERT/CC Current Activity page. ...
    (Cert)
  • CERT Summary CS-2003-03
    ... CERT Summary CS-2003-03 ... we have seen a large volume of reports related to a mass ... on the exploitation of vulnerabilities in Microsoft's RPC ... CERT/CC, please visit the CERT/CC Current Activity page. ...
    (Cert)