Tod Beardsley · @todb
864 followers · 485 posts · Server infosec.exchange

I'm trying to get more serious about actually writing analyses of things that catch my interest. Here's my writeup of #pr_pack mule which is totally the name of this vuln, h/t to @dreadpir8robots .

#attackerkb #pr_pack

Last updated 2 years ago

Tod Beardsley · @todb
821 followers · 429 posts · Server infosec.exchange

All right mastodon. How do I find out who is talking about a particular fresh vuln? I’m going to throw out some hashtags and see what turns up relevant conversation.





Is this a big deal because stack based in a common binary, or a because is capability restricted in ?

freebsd.org/security/advisorie

#infosec #186f495d4be1 #cve_2022_23093 #pingbof #pr_pack #freebsd #bof #setuid #shrug #ping

Last updated 2 years ago

pirate moo🐮 · @apiratemoo
2938 followers · 1161 posts · Server infosec.exchange

freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc

I don't get why people laughed at this CVE (2022-23093).

I initially misread it and took it for a DoS.

I assume an ICMP fragmentation attack could actually DoS it as well (am I wrong here? tell me why), but this actually could RCE from what I understand.

Am I missing something?

#infosec #security #exploitation #exploitsdev #186f495d4be1 #cve_2022_23093 #pingbof #pr_pack

Last updated 2 years ago