| ★ wanayoo — archive 1999 http://search.linuxsecurity.com/advisories/freebsd.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
- Chris Evans has reported a possible DoS in the sunrpc code: A well known bug I first publicised back in 1998 still exists in the FreeBSD libc sunrpc code. Linux glibc, OpenBSD and possibly even Sun fixed the problem back in 1998. - The advisory describes three vulnerabilities in the Kerberos libraries. - The mars_nwe port, versions prior to 0.99.b19_1, contains a remote format string vulerability. - The dc20ctrl port, versions prior to 0.4_1, contains a locally exploitable buffer overflow. - The ja-elvis and ko-helvis ports, versions prior to ja-elvis-1.8.4_1 and ko-helvis-1.8h2_1, contain an exploitable buffer overflow in the elvrec utility. - The ja-xklock port, versions 2.7.1 and earlier, contains an exploitable buffer overflow. - NOTE: It has come to our attention that there are a great deal more users downloading this advisory than the recently released SA-01:18, which also deals with the bind software. The latter advisory details a far more serious vulnerability. - An overflowable buffer related to the processing of transaction signatures (TSIG) exists in all versions of BIND prior to 8.2.3-RELEASE. - The exmh2 port, versions prior to 2.3.1, contains a local vulnerability. - The mysql323-server port, versions prior to 3.23.22, and all mysql322-server ports contain remote vulerabilities. - The tinyproxy port, versions prior to 1.3.3a, contains several remotely exploitable vulnerabilities. - The micq port, versions prior to 0.4.6.1, contains a remotely exploitable buffer overflow. - During internal auditing, sort(1) was found to use easily predictable temporary file names. - A vulnerability was inadvertently introduced into periodic that caused temporary files with insecure file names to be used in the system's temporary directory. - The internal ident server in inetd was found to incorrectly set group privileges according to the user. This allows a malicious user to read the first 16 byes of wheel-accessible files. - crontab allows users to read certain files - Malicious remote users can cause the named daemon to crash, if it is configured to allow zone transfers and recursive queries. - Malicious local users can read arbitrary local files that conform to a valid crontab file syntax. - Local or remote users may cause a denial of service attack against an X server or certain X applications. Local users may obtain elevated privileges with certain X applications. - Due to overloading of the TCP reserved flags field, ipfw and ip6fw incorrectly treat all TCP packets with the ECE flag set as being part of an established TCP connection. - The openssh client fails to check whether agent or X11 forwarding has been negotiated during session setup. - Due to incorrect log parsing, remote users may cause syslog-ng to crash. - An attacker can exploit this vulnerability to overwrite an arbitrary file writable by the user running the shell. - Potential symlink attack exists with previous versions. - An incorrect usage of syslog() in older versions may lead to root compromise. - This may allow users with privileges in one folder to gain the same privileges in another folder. - There were several problems discovered in the procfs code - The bitchx port, versions prior to 1.0c17_1, and ko-bitchx port, versions prior to 1.0c16_3, contains a remote vulnerability. - The ethereal port, versions prior to 0.8.14, contains buffer overflows which allow a remote attacker to crash ethereal or execute arbitrary code on the local system. - The halflifeserver port, versions prior to 3.1.0.4, contains local and remote vulnerabilities through buffer overflows and format string vulnerabilities. - The bitchx port, versions prior to 1.0c17_1, contains a remote vulnerability. - The oops port, versions prior to 1.5.2, contains remote vulnerabilities through buffer and stack overflows in the HTML parsing code. - There were several problems discovered in the procfs code. - The csh and tcsh code creates predictable temporary files when the '<<' operator is used. - There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities. - The telnet protocol allows some environmental variables to affect its operation. - The mod_php ports, versions prior to 3.0.17 and 4.0.3 contain a potential vulnerablilty that may allow a malicious remote user to execute arbitrary code. - The thttpd port, versions prior to 2.20, allows remote viewing of arbitrary files on the local server. - The curl port, versions prior to 7.4.1, allows a client-side exploit through a buffer overflow in the error handling code. - The mgetty port, versions prior to 1.1.22.8.17, contains a vulnerability that may allow local users to create or overwrite any file on the system. - ppp "deny_incoming" does not correctly deny incoming packets. - Of particular relevance is the ability for remote users to cause an arbitrary file on the system to be searched for termcap data by passing the TERMCAP environment variable. - There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities. - Versions of gnupg prior to 1.04 fail to correctly verify multiple signatures contained in a single document. - Versions of netscape prior to 4.76 allow a client-side exploit through a buffer overflow in html code. - Versions of xfce prior to 3.52 contain a startup script which incorrectly allows access to the X display to all other users on the local system. - global port allows remote compromise through CGI script - top allows reading of kernel memory [REISSUED] - tcpdump contains remote vulnerabilities [REISSUED] - An off-by-one error exists in the processing of DNS hostnames which allows a long DNS hostname to crash the getnameinfo() function under certain conditions. - A "format string vulnerability" was discovered in the top(1) utility which allows unprivileged local users to cause the top process to execute arbitrary code. - Several overflowable buffers were discovered in the version of tcpdump included in FreeBSD. - The boa port, versions after 0.92 but prior to 0.94.8.3, contains a vulnerability which allows remote users to view arbitrary files outside the document root. - The pine4 port, versions 4.21 and before, contains a buffer overflow vulnerability. - A "format string vulnerability" was discovered in code used by the vipw utility during an internal FreeBSD code audit in July 2000. - The muh port, versions 2.05c and before, contains a vulnerability which allows remote users to gain the privileges of the user running muh. - A malicious user may be able to read certain files via a finger request. - The LPRng port, versions prior to 3.6.24, contains a potential vulnerability which may allow root compromise from both local and remote systems. - The xpdf port, versions prior to 0.91, contains a race condition due to improper handing of temporary files. - TCP uses weak initial sequence numbers - catopen() and setlocale() are functions which are used to display text in a localized format, e.g. for international users. - The screen port, versions 3.9.5 and before, contains a vulnerability which allows local users to gain root privileges. - The mailman port, versions prior to 2.0b5, contained several locally exploitable vulnerabilities which could be used to gain root privileges. - The listmanager port, versions prior to 2.105.1, contained several locally exploitable buffer overflow vulnerabilities which could be used to gain root privileges. - The eject program is installed setuid root, and contains several exploitable buffers which can be overflowed by local users, yielding root privileges. - Prior to version 1.5.7 in the 1.5 development series, a malicious IRC user could embed command strings in a URL. - The pine4 port, versions 4.21 and before, contained a bug which would cause the program to crash when processing a folder which contains an email message with a malformed X-Keywords header. - The screen port, versions 3.9.5 and before, contains a vulnerability which allows local users to gain root privileges. - The esound port, versions 0.2.19 and earlier, creates a world-writable directory in /tmp owned by the user running the EsounD session - The ELF binary format is used for binary executable programs on modern versions of FreeBSD. - The mopd port contains several remotely exploitable vulnerabilities. An attacker exploiting these can execute arbitrary code on the local machine as root. - Remote users can read files on the local system accessible to the user running netscape, if java is enabled, and may be able to execute arbitrary code on the local system as that user. - Malformed ELF images can cause a system hang - Linux binary compatability mode can cause system compromise - brouted port allows gid kmem compromise - xlockmore port allows reading of password file - zope is an object-based dynamic web application platform. - cvsweb is a CGI script which provides a read-only interface to a CVS repository for browsing via a web interface. - ntop is a utility for monitoring and summarizing network usage, from the command-line or remotely via HTTP. - The proftpd port, versions prior to 1.2.0rc2, contains a vulnerability which allows FTP users, both anonymous FTP users and those with a valid account, to execute arbitrary code as root on the local machine, - dhclient is vulnerable to malicious dhcp server. - FreeBSD advisory delivery clarification - Local or remote users can obtain root access on the system running Kerberos, whether as client or server. - FTP users, including anonymous FTP users, can cause arbitrary commands to be executed as root on the local machine. - Remote users can run arbitrary code as user 'bin' on the local system. - Remote users can cause arbitrary code to be executed as the retrieving user when a POP client retrieves email. - Remote users can cause a FreeBSD system to panic and reboot. - Remote users can cause arbitrary code to be executed as the retrieving user when a POP client retrieves email. - libedit reads config file from current directory leading to potential root compromise. - OpenSSH UseLogin directive permits remote root access - majordomo is not safe to run on multi-user machines - Remote IRC users can cause the local client to crash, and possibly execute code as the local user. - Unprivileged local users can obtain root access. - Remote users can run arbitrary code as user 'bin' on the local system. - Remote anonymous FTP users can cause arbitrary commands to be executed as root on the local machine. - Remote users can cause a FreeBSD system to panic and reboot. - FreeBSD/Alpha platform lacks kernel pseudo-random number generator, some applications fail to detect this. - Remote users with valid SSH credentials may access the ssh server on a non-standard port - Local users can cause arbitrary commands to be executed as root - Local or remote users can obtain root access on the system running krb5. - An unprivileged local user can cause every process on the system to hang during exiting. - gnapster/knapster ports allows remote users to view local files - Lynx ports contain numerous buffer overflows - The gnapster port (version 1.3.8 and earlier) contains a vulnerability which allows remote gnapster users to view any file on the local system which is accessible to the user running gnapster. - The golddig port erroneously installs a level-creation utility setuid root, which allows users to overwrite the contents of arbitrary local files. - libmytinfo allows users to specify an alternate termcap file or entry via the TERMCAP environment variable, however this is not handled securely and contains a overflowable buffer inside the library. - imap-uw allows local users to deny service to any mailbox - imap-uw contains security vulnerabilities for "closed" mail servers - Generic-NQS versions 3.50.7 and earlier contain a security vulnerability which allow a local user to easily obtain root privileges. - Revision -- The mhshow command used for viewing MIME attachments contains a buffer overflow which can be exploited by a specially-crafted email attachment, which will allow the execution of arbitrary code as the local user when the attachment is opened. - mh/nmh/ja-mh/exmh/exmh2/ja-exmh2 ports allow remote execution of binary code. - orville-write port contains local root compromise. - Lynx ports contain numerous buffer overflows - mtr port contains a local root exploit. - The MySQL database server (versions prior to 3.22.32) has a flaw in the password authentication mechanism which allows anyone who can connect to the server to access databases without requiring a password, given a valid username on the database - in other words, the normal password authentication mechanism can be completely bypassed. - An optional third-party port distributed with FreeBSD contains numerous remotely- exploitable buffer overflows which allow an attacker to execute arbitrary commands on the local system, typically as the 'nobody' user. - Two optional third-party ports distributed with FreeBSD can be used to execute commands with elevated privileges, specifically setgid kmem privileges. This may lead to a local root compromise. - There are two buffer overflow vulnerabilities in the the amd daemon - The fts library functions had a buffer overflow in them where which would lead to a core dump when periodic ran the security checking scripts (or other scripts which traverse trees that can be controlled by users). periodic(3) should limit core size to zero to disable core dumps while it is executing commands, but does not do so. In addition, the kernel should not follow symbolic links. All three of these problems caused a situation where it was possible for an attacker could create or overwrite an arbitrary file on the system with a moderate degree of controll of its contents to cause a problem. - The fts library functions had a flaw in them where which would lead to a core dump when periodic ran the security checking scripts (or other scripts which traverse trees that can be controlled by users). periodic(3) should limit core size to zero to disable core dumps while it is executing commands, but does not do so. In addition, the kernel should not follow symbolic links. All three of these problems caused a situation where it was possible for an attacker could create or overwrite an arbitrary file on the system with a moderate degree of controll of its contents to cause a problem. - There are different security problems which can lead to remote root access in these ports or packages. The standard ftp daemon which ships with FreeBSD is not impacted by either of these problems. - A flaw exists in the implementation which allows an attacker to cause arbitrary locations in program executed by the attacker. - A user can set flags and mode on the device which they logged into. Since a bug in login and other similar programs causes the normal chown to fail, this first user will own the terminal of any login. - There is a bug in the IP fragment reassembly code that might lead to a kernel panic. An attacker can create and send a pair of malformed IP packets which are then reassembled into an invalid UDP datagram. Such an UDP datagram would then cause a server to panic and crash. - A denail of service attack can be launched against FreeBSD systems running without one of the patches supplied later in this message. Using a flaw in the interpreation of sequence numbers in the RST packet, malicious users can terminate connections of other users at will. - As can be read in CERT advisory CA-98.01.smurf, there exists a denial of service attack called "smurfing". This attack sends ICMP echo requests to the broadcast address of a network. This results in the source address of the ICMP packets being flooded with ICMP echo replies. Of course, the source address is spoofed. - When creating hard links on file systems, the kernel checks that both the original file and the link to it are located on the same file system. Unfortunately, there is an error in the NFS kernel code in FreeBSD 2.2.* systems that performs this check. - It is possible for a process to open an append-only file according to the limitations of the flags, and then mmap the file shared with write permission even when the file is marked as append-only or immutable. This circumvents the concept of the the append-only flag. - An accelerated open is initiated by a client by sending a new TCP option, called CC, to the server. The kernel keeps a special cache for each host it communicated with, among others containing the value of the last CC option used by the client. A new accelerated open is allowed when the CC sent is larger than the one in the per-host cache. Thus one can spoof complete connections. - Due to a 4.4BSD VM system problem, it is possible to memory-map a read-only descriptor to a character device in read-write mode. - A specific sequence of instructions, starting with the byte codes F0 0F (hex) cause Pentium processors to lock up. This lockup wedges the entire system, requiring a hard reset to correct. Systems that allow users to run arbitrary code are vulnerable to this attack. - A problem exists in most FreeBSD derived stacks that allows a malicious user to send a packet that causes the sytsem to lock up, thus producing a denial of service attack. - A problem exists in the open() syscall that allows processes to obtain a valid file descriptor without having read or write permissions on the file being opened. This is normally not a problem. The FreeBSD way of obtaining the right to do io instructions however, is based on the right to open a specific file (/dev/io). - A problem exists in the procfs kernel code that allows processes to write memory of other processes where it should have been prohibited. - One of the port installation options in sysinstall is to install an anonymous ftp setup on the system. In such a setup, an extra user needs to be created on the system, with username 'ftp'. This user is created with the shell equal to '/bin/date' and an empty password. - The lpd program runs as root. A remote attacker can exploit a buffer overflow to obtain root privs. - Buffer overrun (aka stack overflow) exploits in system supplied and locally installed utilities are commonly used by individuals wishing to obtain unauthorized access to computer systems. The FreeBSD team has been reviewing and fixing the source code pool to eliminate potential exploits based on this technique. Recently, the Australian CERT organization received information of a buffer-overrun vulnerability in the talkd daemon shipped in most modern BSD based systems. - The programs in question store user-supplied information in internal buffers. There is no range checking on length of the data copied into these buffers. A malicious user may be able to overflow these buffers through the use of command line options or via enviornment variables and insert and execute their own code fragment which could be used to obtain unauthorized access to the system - The modstat program has always been installed setuid kmem. Within the program, a buffer overflow can occur. - Due to its nature, the lpr program is setuid root. Unfortunately, the program does not do sufficient bounds checking on arguments which are supplied by users. As a result it is possible to overwrite the internal stack space of the program while it's executing. This can allow an intruder to execute arbitrary code by crafting a carefully designed argument to lpr. As lpr runs as root this allows intruders to run arbitrary commands as root. - The Z-Modem protocol specifies a mechanism which allows the transmitter of a file to execute an arbitrary command string as part of the file transfer. This is typically used to rename files or eliminate temporary files. A malicious "trusted" sender could send down a command that could damage a user's environment. - rdist creates an error message based on a user provided string, without checking bounds on the buffer used. This buffer is on the stack, and can therefore be used to execute arbitrary instructions. - The ppp program does not properly manage user privileges, allowing users to run any program with root privileges. - The authors of perl provide a "suidperl" program for proper processing of setuid perl scripts on systems where race conditions where setuid scripts could be exploited to gain unauthorized access. FreeBSD installs this suidperl program (and a link) as part of the standard installation. However, privilege processing done by this program does not take into account recent functionality extensions in the seteuid/setegid system calls. - A potential problem exists when users specify mask addresses to ipfw(8) using the address:mask syntax. Specifically, whenever the ':' syntax is used, the resulting mask is always 0xffffffff. - The comsat daemon does not properly set privileges before attempting to read mail files for display on a user terminal. - The mount_union and mount_msdos programs invoke another system utility in an insecure fashion while setuid root. - The union filesystem code had problems with certain mount ordering problems. By executing a certain sequence of mount_union commands, an unprivileged local user may cause a system reload. NOTE: This is a different problem than the one discussed in FreeBSD SA-96:09. The workaround for this vulnerability is similar to the one discussed in 96:09, but the proper solution for the unauthorized access problem in 96:09 does not address this vulnerability. - The man program is setuid to the "man" user. By executing a particular sequence of commands, an unprivileged local user may gain the access privileges of the "man" user. However, root access could be obtained with further work. - The sliplogin program is used to allow a remote user to dial into a FreeBSD system and start a SLIP connection. The sliplogin program is typically used as replacement user "shell" in this application. The sliplogin program invokes a child process that may be compromised through the passing of certain environment variables. - Versions of the apache http daemon before release 1.05 do not properly restrict shell meta-characters transmitted to the daemon via form input (via GET or POST). - Bounds checking for syslog error messages was not being performed properly. - Sendmail has the ability to deliver mail to a program on the local system via a pipe. This feature is often used to support automatic mail filtering and vacation programs. This provides a very flexible way to deliver information to an automated task running on a mailserver. Unfortunately, this allows unprivileged users to write tasks that may not properly check for common attacks via the program delivery system. The next release of FreeBSD will now install the sendmail restricted shell utility, smrsh in /usr/libexec and create the directory /usr/libexec/sm.bin to hold programs that may be executed by sendmail to deliver mail to pipes. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |