vendor:
OpenBSD, FreeBSD
by:
caddis
9
CVSS
CRITICAL
BSD chpass exploit
119
CWE
Product Name: OpenBSD, FreeBSD
Affected Version From: OpenBSD 2.5 1998/05/28
Affected Version To: FreeBSD 4.0-RELEASE
Patch Exists: NO
Related CWE: CVE-1999-0099
CPE: o:openbsd:openbsd:2.7
Platforms Tested: OpenBSD 2.7 i386, OpenBSD 2.6 i386, OpenBSD 2.5 1999/08/06, OpenBSD 2.5 1998/05/28, FreeBSD 4.0-RELEASE, FreeBSD 3.5-RELEASE, FreeBSD 3.4-RELEASE, NetBSD 1.4.2
Unknown
TESO BSD chpass exploit
This exploit is for the TESO BSD chpass vulnerability. It allows an attacker to execute arbitrary code with root privileges on vulnerable systems. The exploit works by exploiting a buffer overflow in the chpass utility, which is used to change user passwords on BSD-based operating systems. By sending a specially crafted input, an attacker can overwrite important memory addresses and gain control of the system. This exploit is written in C and includes shellcode for both OpenBSD and FreeBSD systems.
Mitigation:
The best way to mitigate this vulnerability is to apply the latest security patches for the affected operating systems. Additionally, it is recommended to restrict access to the chpass utility and closely monitor system logs for any suspicious activity.