Date: 09 Sep 1994 07:56:49 -0400 From: Pete Hammes Subject: ASSIST 94-28 To: assist-bulletin@assist.MIL -----BEGIN PRIVACY-ENHANCED MESSAGE----- Proc-Type: 4,MIC-CLEAR Content-Domain: RFC822 Originator-Certificate: MIICozCCAgwCAREwDQYJKoZIhvcNAQECBQAwgYYxC zAJBgNVBAYTAlVTMSswKQYDVQQKEyJEZWZlbnNlIEluZm9ybWF0aW9uIFN5c3Rlb XMgQWdlbmN5MTAwLgYDVQQLEydDZW50ZXIgZm9yIEluZm9ybWF0aW9uIFN5c3Rlb XMgU2VjdXJpdHkxGDAWBgNVBAsTD0NvdW50ZXJtZWFzdXJlczAeFw05MzEyMDkxO DU5MTZaFw05NTEyMDkxODU5MTZaMIGxMQswCQYDVQQGEwJVUzErMCkGA1UEChMiR GVmZW5zZSBJbmZvcm1hdGlvbiBTeXN0ZW1zIEFnZW5jeTEwMC4GA1UECxMnQ2Vud GVyIGZvciBJbmZvcm1hdGlvbiBTeXN0ZW1zIFNlY3VyaXR5MRgwFgYDVQQLEw9Db 3VudGVybWVhc3VyZXMxEzARBgNVBAsTCk9wZXJhdGlvbnMxFDASBgNVBAMTC1Bld GUgSGFtbWVzMIGaMAoGBFUIAQECAgQAA4GLADCBhwKBgQDFFJkcaDOuS+6Ai2vmT bwY6JRbhdzPsl6X60hnXruOw2WvrAhc8BTFB+id75m3M55i+Th6MxWH20QHyQq5u yVghOu/s37OxIrj7irNPjtUdPv8b2m4hNGEW53QH6GmXkxLmgLzOhookpoYPC+uw 2MzibDnleVI50d2m//XsWs7hwIBAzANBgkqhkiG9w0BAQIFAAOBgQDHH6CmBoyWU zPlqVnEWYKIBsifqdTJzkKfnoST7NDRIakUP49FP86Cyy1+2AKpUCWaxjq+wGHCH RCNFCCrOwdC9z8XwJal/c69ml6eLRhOoX77ANndpU9E5+eHxP+6Ute6lc63K7+Lz 5xOULjmgaMmKDkTXveVcQO6R2CTY37vcA== Issuer-Certificate: MIICNTCCAZ4CASIwDQYJKoZIhvcNAQECBQAwRDELMAkGA 1UEBhMCVVMxCzAJBgNVBAgTAk1EMSgwJgYDVQQKEx9UcnVzdGVkIEluZm9ybWF0a W9uIFN5c3RlbXMgUENBMB4XDTk0MDIyNTE0NDkxMloXDTk0MDMwNzE0NDkxMlowg YYxCzAJBgNVBAYTAlVTMSswKQYDVQQKEyJEZWZlbnNlIEluZm9ybWF0aW9uIFN5c 3RlbXMgQWdlbmN5MTAwLgYDVQQLEydDZW50ZXIgZm9yIEluZm9ybWF0aW9uIFN5c 3RlbXMgU2VjdXJpdHkxGDAWBgNVBAsTD0NvdW50ZXJtZWFzdXJlczCBmjAKBgRVC AEBAgIEAAOBiwAwgYcCgYEA19l6BN7iTGYEU61qJETIjBh3iAeHzoL8sZ5KwFRZD S/a1KnYlD1zJHR/KeQCOBWW2HzX43TFLCNGU7UD9i6m8AymLe5IJf/bGh0Rne7Jd Q1GAOLw7/J4hE57IMbGETZpzeU1D9IYxiERRNio/oa422lUlS9JZHLA5jaPNcUrX P8CAQMwDQYJKoZIhvcNAQECBQADgYEApkliqAdudoOxvOFmQkOZbSgtlpn61VcNC R7azDNJa2ulevaebptwSTs2OvMeuR/J0Ez4TC7XrJXLVjI5huRAqc+EWGRpZYRMa CARZyE7gGYjUqS7DIQazfskeWiB8zheyW5tCVn+jnB09AZXtgbM6qRjyqrmSdCpg CtfgazIKqI= Issuer-Certificate: MIIB8jCCAVsCAQEwDQYJKoZIhvcNAQECBQAwRDELMAkGA 1UEBhMCVVMxCzAJBgNVBAgTAk1EMSgwJgYDVQQKEx9UcnVzdGVkIEluZm9ybWF0a W9uIFN5c3RlbXMgUENBMB4XDTkzMDUyODE3MTEyN1oXDTk1MDUyODE3MTEyN1owR DELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAk1EMSgwJgYDVQQKEx9UcnVzdGVkIEluZ m9ybWF0aW9uIFN5c3RlbXMgUENBMIGaMAoGBFUIAQECAgQAA4GLADCBhwKBgQDbL xaRlS3u54yyRgVDI5dcE9nlasL8fJqOGlyo7xH2FZnr3kUfsFj7OGiYsr6UbvqwK nyfMIRUrXDUa64leGmft3SK27psDUHOynRSCc40d/HrDf810U5tnTamBKUIMqivK 4GoL0tMRA1eX6hALAvLLgK1HbnwZAo6GqQGW8CIJQIBAzANBgkqhkiG9w0BAQIFA AOBgQDBp5aC6oV6IuFi8JCctq57bew604HHNllgjjp7zdXafq6jctRg2g91k/yFW h19bJC/tNrb0WVwuZOs5L/FToPMNIIHzaW/YSROBmyhTDYaKHZGj0P1+iNjMbHt9 dm1QEHGIfKgBwFidItnOa74DfkXdijlPRnr/+E2Ib6PM+hEfQ== MIC-Info: RSA-MD5,RSA,Y1oaktUOyADWBTg2GHDfcLBgb5V30m7Rqs1HZfFwWNV tjThKKfVyka7tM7pm94jjc6Q+p7xyUyIMS9df9zsCbA2JOxYbVxdhLL3Cy4a9WRC ZgIw3FXwsIgGD4DbJUrxZ8ebfUr1t67L4g4BfQEIXb/72p7ZxqgYvEXquR6eFbvA = <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Automated Systems Security Incident Support Team _____ ___ ___ _____ ___ _____ | / /\ / \ / \ | / \ | | / Integritas / \ \___ \___ | \___ | | < et /____\ \ \ | \ | | \ Celeritas / \ \___/ \___/ __|__ \___/ | |_____\ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Bulletin 94-28 Release date: 9 September 1994, 8:05 AM EDT (GMT -4) SUBJECT: Vulnerability in the IRIX v 5.1 and v5.2 Operating Systems SUMMARY: Recent information regarding a newly-discovered vulnerability in the IRIX v5.1 and IRIX v5.2 operating systems, which allows an unprivileged user to become root. BACKGROUND: This vulnerability has been referred to by various names, including clogin, printer manager, and SGI Help. Advisories issued by SGI and other response teams state that the system is only vulnerable if the user can log into an account on the local system or gain physical access to the console. The vulnerability also exists when the system variable is set defining a different SGI host to be the Help Server. With this feature defined, the remote system can be compromised without directly logging onto the remote system. IMPACT: All SGI platforms running IRIX v5.1 or IRIX v5.2. While a patch has been developed for IRIX v5.2, no patch is planned for IRIX v5.1. ASSIST and the vendor recommend that sites running IRIX v5.1.x apply the workaround described below, then upgrade to IRIX v5.2 as soon as possible. RECOMMENDED SOLUTION: For IRIX 5.2, obtain and install patch65 according to the instructions provided in section B below. If the patch cannot be installed immediately, and upgrading to IRIX v5.2 is not feasible, implement the following work-around in order to disable the vulnerability on the system. A. Workaround: This workaround is recommended for all v5.1 sites, and for those v5.2 sites that cannot immediately obtain and install the patch(es) described in the next section. Note that this workaround will not work on systems that run their help sybsystem off the CD-ROM drive. To install the workaround, perform the following command as root: # versions remove sgihelp.sw.eoe This workaround will disable the vulnerable o/s module. However it will also disable the entire Help subsystem. This will affect other installed software parckages that use the SGI Help subsystem. Certain help functions called from within applications will return non-fatal error messages about the missing subsystem. B. Installing Patches (v5.2 only): There are three patches related to this vulnerability: patch00, patch34, and patch65. PLEASE NOTE: To install the patches after the above workaround has been applied, the system would need to be returned to its initial state prior to installation of the patch. The original Help software can be found on the original software distribution CD labeled as IRIX 5.2. To return the system to itis initial state, perform the following command as root IMMEDIATELY PRIOR TO THE INSTALLATION OF THE PATCH(ES): # inst -f /CDROM/dist/sgihelp.sw.eoe Inst> install sgihelp.sw.eoe Inst> go Patch34 is an update to patch00 which modifies the "inst" program to enable it to handle patch updates. At least one of patch00 or patch34 is required to be installed before installing patch65. To determine if the new "inst" program is already installed on the system, the following command can be issued: # versions patch\* (which will produce output similar to): I = Installed, R = Removed Name Date Description I patchSG0000034 08/10/94 Patch SG0000034 I patchSG0000034.eoe1_sw 08/10/94 IRIX Execution Environment Software I patchSG0000034.eoe1_sw.unix 08/10/94 IRIX Execution Environment If neither patchSG0000034 or patchSG0000000 is loaded, retrieve and install patch65. Otherwise,download both patch34 and patch65. Install patch34 first, then patch65. To install patch34, uncompress and untar patch34.tar.Z" and follow the instructions in the "README.FIRST" file. The checksums for the patch files are as follows: Standard System V MD5 Unix Unix Digital Signature patch34.tar.Z: 11066 15627 1674 31253 859d0debff715c5beaccd02b6bebded patch65.tar: 63059 1220 15843 2440 af8c120f86daab9df74998b31927e397 The patches are available via anonymous FTP from ftp.sgi.com and sgigate.sgi.com in the "/security" directory. SGI is also making the patches available on CDROM. A service contract is not needed in order to obtain these security patches on CDROM. Contact the nearest SGI service provider for distribution. ASSIST would like to thank NASIRC for the information provided in this advisory. <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ASSIST is an element of the Defense Information Systems Agency (DISA), Center for Information Systems Security (CISS), that provides service to the entire DoD community. Constituents of the DoD with questions about ASSIST or computer security security issues, can contact ASSIST using one of the methods listed below. Non-DoD organizations/institutions, contact the Forum of Incident Response and Security Teams (FIRST)representative. To obtain a list of FIRST member organizations and their constituencies send an email to docserver@first.org with an empty "subject" line and a message body containing the line "send first-contacts". ASSIST INFORMATION RESOURCES: To be included in the distribution list for the ASSIST bulletins, send your Milnet (Internet) e-mail address to assist-request@assist.mil. Back issues of ASSIST bulletins, and other security related information, are available from the ASSIST BBS at 703-756-7993/1154 DSN 289-7993/1154, and through anonymous FTP from assist.mil (IP address 199.211.123.11). Note: assist.mil will only accept anonymous FTP connections from Milnet addresses that are registered with the NIC or DNS. ASSIST contact information: PHONE: 800-357-4231 (or 703-756-7974 DSN 289), duty hours are 06:00 to 22:30 EDT (GMT -4) Monday through Friday. During off duty hours, weekends and holidays, ASSIST can be reached via pager at 800-791- 4857. The page will be answered within 30 minutes, however if a quicker response is required, prefix the phone number with "999". ELECTRONIC MAIL: Send to assist@assist.mil. ASSIST BBS: Leave a message for the "sysop". Privacy Enhanced Mail(PEM): ASSIST uses PEM, a public key encryption tool, to digitally sign all bulletins that are distributed through e-mail. The section of seemingly random characters between the "BEGIN PRIVACY-ENHANCED MESSAGE" and "BEGIN ASSIST BULLETIN" contains machine-readable digitalsignature information generated by PEM, not corrupted data. PEM software for UNIX systems is available from Trusted Informatio Systems (TIS) at no cost, and can be obtained via anonymous FTP from ftp.tis.com (IP 192.94.214.96). Note: The TIS software is just one of several implementations of PEM currently available and additional versions are likely to be offered from other sources in the near future. Reference herein to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by ASSIST. The views and opinions of authors expressed herein shall not be used for advertising or product endorsement purposes. -----END PRIVACY-ENHANCED MESSAGE-----