never stop questioning

b-24.ciac-ultrix-v4-v4.1-vulnerability

b-24.ciac-ultrix-v4-v4.1-vulnerability
Posted Sep 23, 1999

b-24.ciac-ultrix-v4-v4.1-vulnerability

MD5 | a08b2860323c51fac689ac4f4965b081

b-24.ciac-ultrix-v4-v4.1-vulnerability

Change Mirror Download
        _____________________________________________________
The Computer Incident Advisory Capability
___ __ __ _ ___
/ | / \ /
\___ __|__ /___\ \___
_____________________________________________________
Information Bulletin

May 1, 1991, 1200 PDT Number B-24

Ultrix V4.0 and V4.1 Vulnerability
________________________________________________________________________
PROBLEM: /usr/bin/chroot is installed with the setuid bit set.
PLATFORM: DEC Ultrix V4.0 and V4.1, all architectures.
DAMAGE: Allows authorized users to gain unauthorized privileges.
SOLUTIONS: Fixed in Ultrix V4.2. Manually change file mode of
/usr/bin/chroot to 700 for Ultrix V4.0 and V4.1
IMPACT OF WORKAROUND: Non-privileged users no longer have access to
the chroot command.
_______________________________________________________________________
Critical /usr/bin/chroot Vulnerability Facts

CIAC has been advised of a vulnerability in DEC's Ultrix V4.0 and V4.1
operating systems running on all architectures. DEC is aware of this
problem, and has corrected it in Ultrix V4.2. The DEC provided fix for
Ultrix V4.0 and V4.1 is:

(login as root)
# chmod 700 /usr/bin/chroot
# ls -l /usr/bin/chroot
(verify the file protections are "-rwx------")


For additional information or assistance, please contact CIAC:

Hal Brand
(415) 422-6312 or (FTS) 532-6312, or

Call CIAC at (415) 422-8193 or (FTS) 532-8193 or
send e-mail to ciac@cheetah.llnl.gov.

Send FAX messages to: (415) 423-0913 or (FTS) 543-0913
_____
The CERT/CC and Digital Equipment Corporation provided information
contained in this bulletin. This document was prepared as an account
of work sponsored by an agency of the United States Government. Neither
the United States Government nor the University of California nor any
of their employees, makes any warranty, express or implied, or assumes
any legal liability or responsibility for the accuracy, completeness,
or usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close