-----BEGIN PGP SIGNED MESSAGE----- ============================================================================ Security Advisory CERT-NL ============================================================================ Author/Source : Don Stikvoort Index : S-97-79 Distribution : World Page : 1 Classification: External Version: 1 Subject : four SUN Solaris 2.3-5 vulnerabilities Date : 04-Nov-97 ============================================================================ By courtesy of SUN Microsystems we received information on vulnerabilities in: * rlogin (buffer overflow - locals can become root) * sysdef (kernel memory eavesdropping - locals can become root) * ftpd/rlogind combination (misuse of trust relation by remote users) * nis_cachemgr (NIS+ attack, polluting the NIS+ global shared cache) Affected: Solaris 2.3/2.4/2.5 CERT-NL recommends to apply the listed patches. =========================================================================== Sun Microsystems, Inc. Security Bulletin Bulletin Number: #00158 Date: October 28, 1997 Cross-Ref: CERT CA-97.06 Title: rlogin 1. Bulletins Topics Sun announces the release of patches for Solaris 2.5.1, 2.5, 2.4, 2.3, (SunOS 5.5.1, 5.5, 5.4, 5.3), SunOS 4.1.4 and 4.1.3_U1 which relate to a vulnerability in rlogin. Sun strongly recommends that you install the patches listed in section 4 immediately on systems running SunOS 5.5.1, 5.5, 5.4, 5.3, 4.1.4, and 4.1.3_U1. 2. Who is Affected Vulnerable: SunOS versions 5.5.1, 5.5.1_x86, 5.5, 5.5_x86, 5.4, 5.4_x86, 5.3, 4.1.4, 4.1.3_U1 The vulnerability is fixed in Solaris 2.6. 3. Understanding the Vulnerability The rlogin program establishes a remote login session. Due to insufficient bounds checking on arguments supplied to rlogin, it is possible to overwrite the internal data space of the rlogin program. As rlogin is setuid root, this vulnerability may be exploited to gain root access. 4. List of Patches The vulnerability in rlogin is fixed by the following patches: OS version Patch ID __________ ________ SunOS 5.5.1 104650-02 SunOS 5.5.1_x86 104651-02 SunOS 5.5 104669-02 SunOS 5.5_x86 104670-02 SunOS 5.4 105254-01 SunOS 5.4_x86 105255-01 SunOS 5.3 105253-01 SunOS 4.1.4 105260-01 SunOS 4.1.3_U1 105259-01 5. Checksum Table The checksum table below shows the BSD checksums (SunOS 4.1.x: /bin/sum; SunOS 5.x: /usr/ucb/sum), SVR4 checksums (SunOS 4.1.x: /usr/5bin/sum; SunOS 5.x: /usr/bin/sum), and the MD5 digital signatures for the above-mentioned patches that are available from: These checksums may not apply if you obtain patches from your answer centers. File Name BSD SVR4 MD5 _______________ _________ __________ ________________________________ 104650-02.tar.Z 13535 97 28313 194 09633D56EE7957B583EA7B56868C041A 104651-02.tar.Z 63944 97 59194 194 62FC76D27F05D9088734AFB2FBA728B4 104669-02.tar.Z 50300 97 53035 194 603DBCACC7E43DB308F6191BC9FA5D69 104670-02.tar.Z 53991 97 53938 193 2AAB302E10CF860B4009E1CF873B1AE7 105254-01.tar.Z 16467 86 40933 172 6C1C5E4A63C07B69E79CFE31308703F0 105255-01.tar.Z 61095 86 58884 172 CE00AF98291E033BEE5E49C049AD6162 105253-01.tar.Z 12622 86 40936 172 382904D4F14E247D17F9E59F1424480D 105260-01.tar.Z 06896 11 12684 22 191C9F074855631D4CCCD136FA267DEE 105259-01.tar.Z 18628 11 19352 22 CCC5434C6F71AE02C5B456CE4C8BDBBE =========================================================================== Sun Microsystems, Inc. Security Bulletin Bulletin Number: #00157 Date: October 28, 1997 Cross-Ref: Title: sysdef 1. Bulletins Topics Sun announces the release of patches for Solaris 2.5.1, 2.5, 2.4, 2.3, (SunOS 5.5.1, 5.5, 5.4, 5.3) which relate to a vulnerability in sysdef. Sun strongly recommends that you install the patches listed in section 4 immediately on systems running SunOS 5.5.1, 5.5, 5.4, and 5.3. 2. Who is Affected Vulnerable: SunOS versions 5.5.1, 5.5.1_x86, 5.5, 5.5_x86, 5.4, 5.4_x86, 5.3 The vulnerability is fixed in Solaris 2.6. 3. Understanding the Vulnerability The sysdef command displays the current system definition, listing hardware devices, pseudo devices, system devices, loadable modules, and values of selected kernel tunable parameters. This vulnerability, if exploited, allows unprivileged users to read kernel memory which may contain sensitive information such as unencrypted passwords. Attackers can subsequently use the information to gain root access. 4. List of Patches The vulnerability in sysdef is fixed by the following patches: OS version Patch ID __________ ________ SunOS 5.5.1 105092-01 SunOS 5.5.1_x86 105093-01 SunOS 5.5 105101-01 SunOS 5.5_x86 105102-01 SunOS 5.4 105099-01 SunOS 5.4_x86 105100-01 SunOS 5.3 105205-01 5. Checksum Table The checksum table below shows the BSD checksums (SunOS 5.x: /usr/ucb/sum), SVR4 checksums (SunOS 5.x: /usr/bin/sum), and the MD5 digital signatures for the above-mentioned patches that are available from: These checksums may not apply if you obtain patches from your answer centers. File Name BSD SVR4 MD5 _______________ _________ __________ ________________________________ 105092-01.tar.Z 18806 104 64648 207 CD282DB673136EE05FB63A59ADF04089 105093-01.tar.Z 29154 103 12815 206 521E2523DFCF6EB7476D40FAE17B4990 105101-01.tar.Z 10425 103 62933 205 E0F25757D958C4FF74B44471B6659532 105102-01.tar.Z 45898 102 45444 204 1E4953774F47C899EB25ACE8D0ED2B18 105099-01.tar.Z 64861 92 23604 183 E35540AC8BFCACED246F11A45E7BE55C 105100-01.tar.Z 61681 91 12641 182 F1C568E5D830D465B01B9892E19DDDAA 105205-01.tar.Z 65019 92 2573 183 951AB33FB3680E0F06C2182D34536725 _______________________________________________________________________________ Sun thanks Marko Laakso (University of Oulu, Finland) for his assistance in this matter. =========================================================================== Sun Microsystems, Inc. Security Bulletin Bulletin Number: #00156 Date: October 28, 1997 Cross-Ref: Title: ftpd/rlogind 1. Bulletins Topics Sun announces the release of patches for Solaris 2.5.1, 2.5, 2.4, 2.3, (SunOS 5.5.1, 5.5, 5.4, 5.3), SunOS 4.1.4, and 4.1.3_U1, which relate to vulnerabilities in ftpd/rlogin. Sun strongly recommends that you install the patches listed in section 4 immediately on systems running SunOS 5.5.1, 5.5, 5.4, 5.3, 4.1.4, and 4.1.3_U1. 2. Who is Affected Vulnerable: SunOS versions 5.5.1, 5.5.1_x86, 5.5, 5.5_x86, 5.4, 5.4_x86, 5.3, 4.1.4, and 4.1.3_U1 The vulnerability is fixed in Solaris 2.6. 3. Understanding the Vulnerability The daemon in.ftpd is the Internet File Transfer Protocol (FTP) server process and the daemon in.rlogind is the rlogin server process. This vulnerability, if exploited, allows an unprivileged user to connect from an ftp server's data port to a rlogin server on a host that trusts the host that the ftp server resides on. If exploited, attackers may execute arbitrary commands on the attacked host. 4. List of Patches The vulnerability in ftpd/rlogind is fixed by the following patches: OS version Patch ID __________ ________ SunOS 5.5.1 103603-05 104935-01 SunOS 5.5.1_x86 103604-05 104936-01 SunOS 5.5 103577-06 104933-01 SunOS 5.5_x86 103578-06 104934-01 SunOS 5.4 101945-51 SunOS 5.4_x86 101946-45 SunOS 5.3 104938-01 SunOS 4.1.4 104477-03 SunOS 4.1.3_U1 104454-03 5. Checksum Table The checksum table below shows the BSD checksums (SunOS 4.1.x: /bin/sum; SunOS 5.x: /usr/ucb/sum), SVR4 checksums (SunOS 4.1.x: /usr/5bin/sum; SunOS 5.x: /usr/bin/sum), and the MD5 digital signatures for the above-mentioned patches that are available from: These checksums may not apply if you obtain patches from your answer centers. File Name BSD SVR4 MD5 _______________ _________ __________ _______________________________ 103603-05.tar.Z 35241 180 26091 359 F88341AFCA8E0BDA0CDA3D5D643A0A6B 104935-01.tar.Z 37614 91 8235 182 DC35D86C7E10AC808822C579B3D2768E 103604-05.tar.Z 32337 169 1518 338 7DE29C6ADBE421BE0205FB073037F20A 104936-01.tar.Z 56022 96 15068 192 E7121D9A75034D1265B7284129A55D89 103577-06.tar.Z 40184 179 1545 358 F5A34940EAD0745BC7E156DF789B49AC 104933-01.tar.Z 00691 91 46319 182 812B7A3A003F7A0A4E51F142FB7DF178 103578-06.tar.Z 04500 169 16233 338 EBAE43827BB84B7CD199B379D5FF362E 104934-01.tar.Z 61481 96 2099 192 AFF2D82DFB54620D8E86CE81873F4A83 101945-51.tar.Z 19354 10914 1335 21827 A654CCB9C09E8E9AE8E96F6977BF7AB5 101946-45.tar.Z 54871 5544 58856 11087 B9CFDA275F39F1F28031DF7B4F39C275 104938-01.tar.Z 00944 107 30171 213 692E6E7298068AF81398AE17220F8BB0 104477-03.tar.Z 44658 85 10415 170 E36EF932BE48BE3A88552B29C00EC748 104454-03.tar.Z 37033 85 18242 170 D58ABFDEC3A15795353854F19DAD158B _______________________________________________________________________________ Sun acknowledges with thanks AUSCERT for their assistance in the preparation of this bulletin. =========================================================================== Sun Microsystems, Inc. Security Bulletin Bulletin Number: #00155 Date: October 28, 1997 Cross-Ref: Title: nis_cachemgr 1. Bulletins Topics Sun announces the release of patches for Solaris 2.5.1, 2.5, and 2.4 (SunOS 5.5.1, 5.5, and 5.4) which relate to a vulnerability in nis_cachemgr. Sun estimates that the release of a patch for Solaris 2.3 (SunOS 5.3) that relate to the same vulnerability will be available within 4 weeks of the date of this bulletin. Sun strongly recommends that you install the patches listed in section 4 immediately on systems running SunOS 5.5.1, 5.5, and 5.4 which use NIS+. 2. Who is Affected Vulnerable: SunOS versions 5.5.1, 5.5.1_x86, 5.5, 5.5_x86, 5.4, 5.4_x86, 5.3 Not vulnerable: All other supported versions of SunOS. The vulnerability does not exist in Solaris 2.6. 3. Understanding the Vulnerability NIS+ clients run nis_cachemgr, a NIS+ utility that caches location information about NIS+ servers. This vulnerability, if exploited, allows attackers to add bogus directory objects to the global shared cache, in effect specifying rogue NIS+ servers that are under their control. 4. List of Patches The vulnerability in nis_cachemgr is fixed by the following patches: OS version Patch ID __________ ________ SunOS 5.5.1 103612-33 SunOS 5.5.1_x86 103613-32 SunOS 5.5 103187-29 SunOS 5.5_x86 103188-29 SunOS 5.4 101973-32 SunOS 5.4_x86 101974-32 SunOS 5.3 101318-89 (to be released in 4 weeks) 5. Checksum Table The checksum table below shows the BSD checksums (SunOS 5.x: /usr/ucb/sum), SVR4 checksums (SunOS 5.x: /usr/bin/sum), and the MD5 digital signatures for the above-mentioned patches that are available from: These checksums may not apply if you obtain patches from your answer centers. File Name BSD SVR4 MD5 _______________ __________ __________ ________________________________ 103612-33.tar.Z 42409 3248 60555 6495 63408A137DBE6BEEDAECFA49674F0E5A 103613-32.tar.Z 08972 2939 41390 5878 E613588ADA2845DA2CEDE801FE247ED2 103187-29.tar.Z 47938 3240 14585 6479 D681C0BB1C4267418AEB20F56DDE7FD3 103188-29.tar.Z 36871 2919 14150 5838 F7184B433BF9EDCBA99E81D2039F355A 101973-32.tar.Z 55144 956 44485 1911 A802DA901090B52A27BDC6AE0D386C13 101974-32.tar.Z 41770 826 48991 1652 91AB26639B6CB0902ADE354999751826 =========================================================================== CERT-NL is the Computer Emergency Response Team for SURFnet customers. SURFnet is the Dutch network for educational, research and related institutes. CERT-NL is a member of the Forum of Incident Response and Security Teams (FIRST). All CERT-NL material is available under: http://www.surfnet.nl/surfnet/security/cert-nl.html ftp://ftp.surfnet.nl/surfnet/net-security In case of computer or network security problems please contact your local CERT/security-team or CERT-NL (if your institute is NOT a SURFnet customer please address the appropriate (local) CERT/security-team). CERT-NL is one/two hour(s) ahead of UTC (GMT) in winter/summer, i.e. UTC+0100 in winter and UTC+0200 in summer (DST). Email: cert-nl@surfnet.nl ATTENDED REGULARLY ALL DAYS Phone: +31 302 305 305 BUSINESS HOURS ONLY Fax: +31 302 305 329 BUSINESS HOURS ONLY Snailmail: SURFnet bv Attn. CERT-NL P.O. Box 19035 NL - 3501 DA UTRECHT The Netherlands NOODGEVALLEN: 06 52 87 92 82 ALTIJD BEREIKBAAR EMERGENCIES : +31 6 52 87 92 82 ATTENDED AT ALL TIMES CERT-NL'S EMERGENCY PHONENUMBER IS ONLY TO BE USED IN CASE OF EMERGENCIES: THE SURFNET HELPDESK OPERATING THE EMERGENCY NUMBER HAS A *FIXED* PROCEDURE FOR DEALING WITH YOUR ALERT AND WILL IN REGULAR CASES RELAY IT TO CERT-NL IN AN APPROPRIATE MANNER. CERT-NL WILL THEN CONTACT YOU. =========================================================================== -----BEGIN PGP SIGNATURE----- Version: 2.6.3i Charset: cp850 iQCVAwUBNF6DgkU5nQkWIq1FAQFi2wQAyryfy0wdgr2SHJuRYu1n1z1Mt/HOkBZC gX4LaQMyxOafRKy9mMPhMawUDFO75sxd/wn0Rf4nhakBQuyrA9ioPSgR7JhQ2cXE bbgfTX7hMxQwq18dZ7SMGkcLmFgjsjO+SN10V6jc9cZZ6Rh/PTm9CVN14b543IRT z1eJWlGGXv0= =LtQq -----END PGP SIGNATURE-----