oss-sec mailing list archives

CVE Request -- mosh (and probably vte too): mosh server DoS (long loop) due improper parsing of terminal parameters in terminal dispatcher


From: Jan Lieskovsky <jlieskov () redhat com>
Date: Tue, 22 May 2012 15:53:30 +0200

Hello Kurt, Steve, vendors,

  based on:
  [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=673871
  [2] https://github.com/keithw/mosh/issues/271

A) Mosh issue:
==============
A denial of service flaw was found in the way mosh, a remote terminal application, performed processing of parameters that have been passed to the terminal in the terminal dispatcher class (previously there was no limit for the count of parameters, which were allowed to be passed to the dispatcher). A remote atttacker could use this flaw to cause a denial of service (mosh server to enter long for loop when trying to process the paramaters) via specially-crafted escape sequence string.

Upstream ticket:
[3] https://github.com/keithw/mosh/issues/271

Relevant upstream patch:
[4] https://github.com/keithw/mosh/commit/9791768705528e911bfca6c4d8aa88139035060e

References:
[5] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=673871
[6] https://bugzilla.redhat.com/show_bug.cgi?id=823943

Could you allocate a CVE id for this? (issue confirmed by mosh upstream)

B) vte issue:
=============
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=673871#5

there is similar issue in vte too (Gnome bug private for now):
https://bugzilla.gnome.org/show_bug.cgi?id=676090

Cc-ed Behdad Esfahbod on this post to clarify, what are the upstream plans
regarding this report in vte and if the CVE id has been already assigned for
it.

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


Current thread: