SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#569272

System V derived login contains a remotely exploitable buffer overflow

Overview

A remotely exploitable buffer overflow exists in implementations of login, derived from System V. An attacker can use this vulnerability to gain the privileges of the process that invoked login, user root in the cases of in.telnetd, or in.rlogind. We have been able to determine that several vendors are affected.

I. Description

Implementations of login, derived from System V, use a fixed-size buffer to store environment and argument variables that are received from other programs. This buffer can be overflowed by inputing numerous variables. An attacker can use this vulnerability to gain the privileges of the process that invoked login. If an attacker with a local shell invokes login directly, they can only gain the privileges of the shell they already have. However, if the attacker can invoke login via a suid root program, such as the in.telnetd or in.rlogind daemons, they can gain the privileges of the invoking suid program, typically root. And of course, because in.telnetd and in.rlogind are available over the network, an attacker without any previous access to the system could use this vulnerability to gain root access directly.

An exploit exists and may be circulating.

II. Impact

A remote intruder can gain a root shell.

III. Solution

Apply a patch when one becomes available. If patches are not available for your version, upgrade to a supported version and apply all patches.

Disable telnet, rlogin, and other programs that use login for authentication. Use programs that use SSH instead and do not use login by default.

Systems Affected

VendorStatusDate NotifiedDate Updated
AppleNot Vulnerable25-Oct-2001
BSDINot Vulnerable12-Nov-2001
CalderaNot Vulnerable25-Oct-2001
CiscoVulnerable11-Apr-2002
Compaq Computer CorporationNot Vulnerable12-Nov-2001
CrayNot Vulnerable12-Nov-2001
Hewlett PackardVulnerable19-Dec-2001
IBMVulnerable21-Dec-2001
MandrakeSoftNot Vulnerable12-Dec-2001
NCRUnknown7-Jan-2002
NetBSDNot Vulnerable12-Nov-2001
Red HatNot Vulnerable24-Oct-2001
SCOVulnerable14-Dec-2001
SGIVulnerable18-Dec-2001
SunVulnerable17-Dec-2001

References


http://xforce.iss.net/alerts/advise105.php
http://www.securityfocus.com/bid/3681

Credit

Our thanks to Mark Dowd and ISS for the report and information contained in their advisory and to Sun Microsystems for their help in identifing the location of the vulnerability.

This document was written by Jason Rafail.

Other Information

Date Public:2001-12-12
Date First Published:2001-12-12
Date Last Updated:2002-04-11
CERT Advisory:CA-2001-34
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:18.00
Document Revision:36

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader