SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#580124

MIT Kerberos (krb5) krshd and v4rcp do not properly validate setuid() or seteuid() calls

Overview

Privilege escalation vulnerabilities in MIT krb5 krshd and v4rcp may allow an authenticated attacker to execute arbitrary code.

I. Description

The MIT krb 5 krshd and v4rcp programs contain multiple privilege escalation vulnerabilities. MIT krb5 Security Advisory 2006-001 states that the vulnerabilities "...result when the OS implementations of setuid() or seteuid() can fail due to resource exhaustion when changing to an unprivileged user ID."

From MIT krb5 Security Advisory 2006-001:

The following vulnerabilities may result from unchecked calls to setuid(), and are believed to only exist on Linux and AIX:

  • Unchecked calls to setuid() in krshd may allow a local privilege escalation leading to execution of programs as root.
  • Unchecked calls to setuid() in the v4rcp may allow a local privilege escalation leading to reading, writing, or creating files as root. v4rcp is the remote end of a krb4-authenticated rcp operation, but may be executed directly by an attacker, as it is a setuid program.

II. Impact

An authenticated, remote attacker may be able to execute arbitrary code with root privileges.

III. Solution

Apply a patch or upgrade

From MIT krb5 Security Advisory 2006-001: "The upcoming krb5-1.5.1 and krb5-1.4.4 releases will include fixes for these vulnerabilities." MIT has also released patches for krb 5-1.5 and krb5-1.4.3. See the Systems Affected section of this document for information about specific vendors.

Disable vulnerable programs

From MIT krb5 Security Advisory 2006-001: "Disable krshd and v4rcp, and remove the setuid bit from the ksu binary and the ftpd binary."

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable18-Aug-2006
AttachmateWRQ, Inc.Not Vulnerable23-Aug-2006
Conectiva Inc.Unknown28-Jul-2006
Cray Inc.Unknown28-Jul-2006
CyberSafe, Inc.Unknown28-Jul-2006
Debian GNU/LinuxUnknown24-Aug-2006
EMC, Inc. (formerly Data General Corporation)Unknown28-Jul-2006
Engarde Secure LinuxUnknown28-Jul-2006
F5 Networks, Inc.Unknown28-Jul-2006
Fedora ProjectUnknown28-Jul-2006
FreeBSD, Inc.Unknown28-Jul-2006
FujitsuUnknown28-Jul-2006
Gentoo LinuxVulnerable16-Aug-2006
Heimdal Kerberos ProjectUnknown28-Jul-2006
Hewlett-Packard CompanyUnknown28-Jul-2006
IBM CorporationVulnerable8-Aug-2006
IBM Corporation (zseries)Unknown28-Jul-2006
IBM eServerUnknown28-Jul-2006
Immunix Communications, Inc.Unknown28-Jul-2006
Ingrian Networks, Inc.Unknown28-Jul-2006
Juniper Networks, Inc.Not Vulnerable8-Aug-2006
KTH Kerberos TeamUnknown28-Jul-2006
Mandriva, Inc.Unknown24-Aug-2006
Microsoft CorporationUnknown28-Jul-2006
MIT Kerberos Development TeamVulnerable8-Aug-2006
MontaVista Software, Inc.Unknown28-Jul-2006
NEC CorporationUnknown28-Jul-2006
NetBSDUnknown28-Jul-2006
NokiaUnknown28-Jul-2006
Novell, Inc.Unknown28-Jul-2006
OpenBSDUnknown28-Jul-2006
Openwall GNU/*/LinuxUnknown28-Jul-2006
QNX, Software Systems, Inc.Unknown28-Jul-2006
Red Hat, Inc.Unknown28-Jul-2006
Silicon Graphics, Inc.Unknown28-Jul-2006
Slackware Linux Inc.Unknown28-Jul-2006
Sony CorporationUnknown28-Jul-2006
Sun Microsystems, Inc.Unknown28-Jul-2006
SUSE LinuxUnknown28-Jul-2006
The SCO GroupUnknown28-Jul-2006
Trustix Secure LinuxUnknown28-Jul-2006
TurbolinuxUnknown28-Jul-2006
UbuntuUnknown28-Jul-2006
UnisysUnknown28-Jul-2006
Wind River Systems, Inc.Unknown28-Jul-2006

References


http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2006-001-setuid.txt
http://www.die.net/doc/linux/man/man8/kshd.8.html
http://www.die.net/doc/linux/man/man1/v4rcp.1.html

Credit

These vulnerabilities were reported by the MIT Kerberos Development Team.

This document was written by Ryan Giobbi and Art Manion.

Other Information

Date Public:2006-07-26
Date First Published:2006-08-08
Date Last Updated:2006-08-24
CERT Advisory: 
CVE-ID(s):CVE-2006-3083
NVD-ID(s):CVE-2006-3083
US-CERT Technical Alerts: 
Metric:6.91
Document Revision:39

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader