GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Saturday, 12-Apr-2025 01:16:44 JSTWill DormannWill Dormann
    in reply to

    And per the excellent folks at watchTowr, we can see what the vulnerability is:
    A stack buffer overflow in X-Forwarded-For

    No need to find a specific endpoint or do something clever. Simply make a web request to anywhere on an ICS system with a large X-Forwarded-For HTTP header and you'll get a stack buffer overflow on the system. 🤦♂️

    And due to the fact that the Ivanti web server does a fork() without a corresponding exec(), we get the same memory layout every single time.

    Now, about Ivanti's use of remediated... The function where the overflow happens just happens to have been rewritten in a way that avoids the overflow.

    Did Ivanti recognize the possibility of a stack buffer overflow and not recognize it as a security issue? Or did they just happen to change code to accidentally avoid the overflow (and decide to use exploit mitigations as well).

    You decide...

    In conversationabout a month ago from infosec.exchangepermalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/140/413/280/971/original/0ad30e70a74288ae.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/141/105/205/085/original/68fe07f0072d0c64.png

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/281/708/474/807/766/original/d238035bd107bc9f.png

    4. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/146/260/123/934/original/dccbbd6e0aa12435.png
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.