what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Securstar DriveCrypt Denail Of Service / Privilege Escalation

Securstar DriveCrypt Denail Of Service / Privilege Escalation
Posted Jul 21, 2011
Authored by Neil Kettle

Securstar DriveCrypt suffers from local kernel denial of service, memory disclosure, and privilege escalation vulnerabilities.

tags | advisory, denial of service, kernel, local, vulnerability
SHA-256 | 06433555ac06a393802719b982d7c7ba91990e26bbafd8a88fcab83f72925f4c

Securstar DriveCrypt Denail Of Service / Privilege Escalation

Change Mirror Download
===============================ADVISORY===============================
Advisory: Securstar - DriveCrypt - Local Kernel
Denial of Service/Memory Disclosure/Privilege Escalation
Advisory ID: DSEC-2011-0001
Author: Neil Kettle, Digit Security Ltd
Affected Software: Securstar DriveCrypt
Vendor URL: http://www.securstar.com
Vendor Status: 'patched'
Category: Denial of Service/Memory Disclosure/Privilege
Escalation
Date Reported: 2009/12/07
Last Modified: 2011/07/20
Release Date: 2011/07/20
===============================ADVISORY===============================

Description
-----------
Multiple vulnerabilities have been discovered in Securstar DriveCrypt kernel
drivers, the vulnerabilities exist due to several somewhat systemic issues in
the validation of user-supplied pointers and trust thereof, use of user-supplied
parameters to privileged kernel functionality and finally, the lack of bounds
checking in unbounded copy operations resulting in buffer overflows.

Analysis
--------
Numerous vulnerabilities exists due to a complete lack of validation of user-
supplied pointers contained within structures passed as arguments to the IOCTL
interface exported from the globally accessible "\\.\DCR" device.

Exploitation
------------
An exploit will be made available to the public in due course at the
following URL,

http://www.digit-labs.org/
http://www.digit-security.com/research.php

Technologies Affected
------------------------------
Securstar - DriveCrypt (<= 5.2)


Vendor Response
------------------------------
http://www.securstar.com/press.php?id_press=405


Disclosure Timeline
------------------------------
7th December 2009 - Vendor Disclosure
10th June 2011 - Vendor Releases Patches


Credits
------------------------------
Neil Kettle of Digit Security Ltd


About Digit Security Ltd
----------------------------------
Digit Security is a computer security consultancy based in the United
Kingdom, albeit with a slight difference. The company is a co-operatively
controlled entity comprised of professionals who are experts in their
respective fields. Thus, as a corollary, nearly everyone at Digit Security
is a both a Consultant, Developer and a Director.

Web: www.digit-security.com
Email: research@digit-security.com

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close