SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#911505

pam_xauth may insecurely forward "X MIT-Magic-Cookies" to new sessions

Overview

A vulnerability exists in pam_xauth that may allow a local attacker to gain access to an administrator's X session.

I. Description

pam_xauth is used to forward xauth keys (or cookies) between users. From the pam_xauth man page:

    Without pam_xauth, when xauth is enabled and a user uses the su command to
    assume superuser priviledges, that user is not able to run X commands as
    root without somehow giving root access to the xauth key used for the
    current X session. pam_xauth solves the problem by forwarding the key from
    the user running su (the source user) to the user whose identity the source
    user is assuming (the target user) when the session is created, and
    destroying the key when the session is torn down.

If a local attacker can cause the system administrator to su to the attacker's account, the attacker may be able to gain access to an administrator's X session. For further technical details, please see Andreas Beck's advisory.

II. Impact

A local attacker may be able to gain access to an administrator's X session.

III. Solution

Apply a patch from your vendor.

Systems Affected

VendorStatusDate NotifiedDate Updated
3ComUnknown5-May-2003
AlcatelUnknown5-May-2003
Apple Computer Inc.Not Vulnerable7-May-2003
AT&TUnknown5-May-2003
AvayaUnknown5-May-2003
BSDIUnknown5-May-2003
Cisco Systems Inc.Unknown5-May-2003
Computer AssociatesUnknown5-May-2003
ConectivaUnknown5-May-2003
Cray Inc.Unknown5-May-2003
D-Link SystemsUnknown5-May-2003
Data GeneralUnknown5-May-2003
DebianNot Vulnerable5-May-2003
EngardeUnknown5-May-2003
Extreme NetworksUnknown5-May-2003
F5 NetworksUnknown5-May-2003
Foundry Networks Inc.Not Vulnerable7-May-2003
FreeBSDUnknown5-May-2003
FujitsuNot Vulnerable17-Jun-2003
Hewlett-Packard CompanyUnknown5-May-2003
HitachiNot Vulnerable7-May-2003
IBMNot Vulnerable7-May-2003
Ingrian NetworksNot Vulnerable7-May-2003
IntelUnknown5-May-2003
Juniper NetworksUnknown5-May-2003
LachmanUnknown5-May-2003
Lotus SoftwareUnknown5-May-2003
Lucent TechnologiesUnknown5-May-2003
MandrakeSoftVulnerable5-May-2003
Microsoft CorporationUnknown5-May-2003
MontaVista SoftwareUnknown5-May-2003
Multi-Tech Systems Inc.Unknown5-May-2003
MultinetUnknown5-May-2003
NEC CorporationUnknown5-May-2003
NetBSDUnknown5-May-2003
NetScreenNot Vulnerable7-May-2003
Network ApplianceUnknown5-May-2003
NeXTUnknown5-May-2003
NokiaUnknown5-May-2003
Nortel NetworksUnknown5-May-2003
OpenBSDUnknown5-May-2003
Openwall GNU/*/LinuxVulnerable7-May-2003
Oracle CorporationUnknown5-May-2003
Red Hat Inc.Vulnerable7-May-2003
Redback Networks Inc.Unknown5-May-2003
Riverstone NetworksUnknown5-May-2003
SCOUnknown5-May-2003
SequentUnknown5-May-2003
SGIUnknown5-May-2003
Sony CorporationUnknown5-May-2003
Sun Microsystems Inc.Unknown5-May-2003
SuSE Inc.Unknown5-May-2003
UnisysUnknown5-May-2003
Wind River Systems Inc.Unknown5-May-2003
WirexUnknown5-May-2003
Xerox CorporationNot Vulnerable30-May-2003
ZyXELUnknown5-May-2003

References


http://marc.theaimsgroup.com/?l=bugtraq&m=104431622818954&w=2
http://www.securityfocus.com/bid/6753
http://www.rt.com/man/pam_xauth.8.html

Credit

This vulnerability was discovered by Andreas Beck.

This document was written by Ian A Finlay.

Other Information

Date Public:2003-02-03
Date First Published:2003-05-04
Date Last Updated:2003-06-17
CERT Advisory: 
CVE-ID(s):CAN-2002-1160
NVD-ID(s):CAN-2002-1160
US-CERT Technical Alerts: 
Metric:12.94
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader