From owner-doc-jp-work@jp.FreeBSD.org Tue Aug  6 22:44:06 2002
Received: (from daemon@localhost)
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) id g76Di6231527;
	Tue, 6 Aug 2002 22:44:06 +0900 (JST)
	(envelope-from owner-doc-jp-work@jp.FreeBSD.org)
Received: from wasley.bl.mmtr.or.jp (wasley.bl.mmtr.or.jp [210.228.160.21])
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) with SMTP/inet id g76Di5n31520
	for <doc-jp-work@jp.FreeBSD.org>; Tue, 6 Aug 2002 22:44:05 +0900 (JST)
	(envelope-from rushani@bl.mmtr.or.jp)
Received: (qmail 11007 invoked from network); 6 Aug 2002 22:44:03 +0900
Received: from unknown (HELO localhost) (210.165.137.196)
  by mx.bl.mmtr.or.jp with SMTP; 6 Aug 2002 22:44:03 +0900
Date: Tue, 06 Aug 2002 22:44:11 +0900 (JST)
Message-Id: <20020806.224411.11600293.rushani@bl.mmtr.or.jp>
To: doc-jp-work@jp.FreeBSD.org
From: Hideyuki KURASHINA <rushani@bl.mmtr.or.jp>
In-Reply-To: <20020806.172153.55999851.hrs@eos.ocn.ne.jp>
References: <200208052351.g75Np6cY097801@freefall.freebsd.org>
	<20020806.172153.55999851.hrs@eos.ocn.ne.jp>
X-PGP-Public-Key: http://www.bl.mmtr.or.jp/~rushani/public_key.txt
X-PGP-Fingerprint: A052 6F98 6146 6FE3 91E2  DA6B F2FA 2088 439A DC57
X-URL: http://www.bl.mmtr.or.jp/~rushani/
X-Mailer: Mew version 3.0.54 on Emacs 21.2 / Mule 5.0 (SAKAKI)
Mime-Version: 1.0
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Transfer-Encoding: 7bit
Reply-To: doc-jp-work@jp.FreeBSD.org
Precedence: list
X-Sequence: doc-jp-work 465
Subject: [doc-jp-work 465] Re: ANNOUNCE: FreeBSD Security Advisory
 FreeBSD-SA-02:36.nfs
Errors-To: owner-doc-jp-work@jp.FreeBSD.org
Sender: owner-doc-jp-work@jp.FreeBSD.org
X-Originator: rushani@bl.mmtr.or.jp
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+020727

$BARIJ$G$9(B.

>>> On Tue, 06 Aug 2002 17:21:53 +0900 (JST), Hiroki Sato <hrs@eos.ocn.ne.jp> said:

> $B:4F#!wEl5~M}2JBg3X$G$9!#(B
> 
>  02:36 $B$H(B 02:37 $B$G$9!#(B

$B$*$D$+$l$5$^$G$9(B.

>   # $BLu$7$E$i$$$C$9$M$'!#(B

# ^^;


> FreeBSD $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG(B
> =============================================================================
> FreeBSD-SA-02:36.nfs (2002-08-05)
>  * Bug in NFS server code allows remote denial of service
> =============================================================================
[...]
> II.  $BLdBj$N>\:Y(B - Problem Description
> 
> A part of the NFS server code charged with handling incoming RPC
> messages had an error which, when the server received a message with a
> zero-length payload, would cause it to reference the payload from the
> previous message, creating a loop in the message chain.  This would
> later cause an infinite loop in a different part of the NFS server
> code which tried to traverse the chain.
> NFS $B%5!<%P$N%3!<%I$K$*$1$k!"E~Ce(B RPC $B%a%C%;!<%8$N=hM}$r(B

$B!VE~Ce(B RPC $B%a%C%;!<%8!W$C$F0lHLE*$J8F$SJ}$J$N$G$7$g$&$+(B.
# $B!VE~Ce$7$?(B RPC $B%a%C%;!<%8!W$H$7$?J}$,FI$_$d$9$$$+$J$H;W$$$^$9(B.

> III. $B1F6AHO0O(B - Impact
> 
> Certain Linux implementations of NFS produce zero-length RPC messages
> in some cases.  A FreeBSD system running an NFS server may lock up
> when such clients connect.
> Linux $B$N(B NFS $B<BAu$N0lIt$K$O!"$"$k>r7o2<$G%G!<%?%5%$%:$,(B 0 $B$N(B
> RPC $B%a%C%;!<%8$r@8@.$9$k$b$N$,$"$j$^$9!#(BNFS $B%5!<%P$H$7$FF0:n$7$F$$$k(B
> FreeBSD $B%7%9%F%`$O!"$=$N$h$&$J%/%i%$%"%s%H$,@\B3$7$?>l9g$K(B

$B!V!D$,@\B3$7$?>l9g$K!W$@$H@\B3$7$?=V4V$K%"%&%H$C$]$$$N$G(B,
$B!V!D$,@\B3$7$F$/$k>l9g$K!W$NJ}$,$$$$$s$8$c$J$$$G$7$g$&$+(B.

> $B%m%C%/%"%C%W$7$F$7$^$&2DG=@-$,$"$j$^$9!#(B

$B!V%m%C%/%"%C%W!W$O2?$+F|K\8l$KLu$7$?$$$H$3$m!D(B.
# lock up $B$J$i%$%a!<%8$,$o$/$s$G$9$,(B, $B%+%?%+%J$@$H%Q%C$H$7$^$;$s(B.


> FreeBSD $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG(B
> =============================================================================
> FreeBSD-SA-02:37.kqueue (2002-08-05)
>  * local users can panic the system using the kqueue mechanism
> =============================================================================
[...]
> I.   $BGX7J(B - Background
> 
> The kqueue mechanism allows a process to register interest in
> particular events on particular file descriptors, and receive
> asynchronous notification when these events occur on the selected
> descriptors.
> kqueue $B$O!"%W%m%;%9$,%U%!%$%k5-=R;R$GH/@8$9$k%$%Y%s%H$r4F;k$G$-$k(B

$B!V!D%$%Y%s%H$rEPO?$G$-$k!W$G$O$J$$$N$G$9$+(B?

-- rushani
