what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

al-9604s.vul

al-9604s.vul
Posted Sep 23, 1999

al-9604s.vul

SHA-256 | e9bdef876177c79971c8adcc214140e6565c8124d6c9ce98326853ce00872904

al-9604s.vul

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

=============================================================================
AL-96.04 AUSCERT Alert
Vulnerability in Solaris 2.x vold
2 August 1996
- -----------------------------------------------------------------------------

AUSCERT has received a report of a vulnerability in the Sun Microsystems
Solaris 2.x distribution involving the Volume Management daemon, vold(1M).
This program is used to help manage CDROM and floppy devices.

This vulnerability may allow a local user to gain root privileges.

Exploit details involving this vulnerability have been made publicly
available.

At this stage, AUSCERT is not aware of any official patches. AUSCERT
recommends that sites take the actions suggested in Section 3 until official
patches are available.

- -----------------------------------------------------------------------------

1. Description

The Volume Management daemon, vold(1M), manages the CDROM and floppy
devices. For example, it provides the ability to automatically detect,
and then mount, removable media such as CDROMs and floppy devices.

vold is part of the Solaris 2.x Volume Management package (SUNWvolu).
It is executed as a background daemon on system startup and runs as root.

When vold detects that a CDROM or floppy has been inserted into a drive,
it is configured to automatically mount the media, making it available
to users. Part of this process includes the creation of temporary files,
which are used to allow the Openwindows File Manager, filemgr(1), to
determine that new media has been mounted. These files are created by
the action_filemgr.so shared object which is called indirectly by vold
through rmmount(1M). The handling of these files is not performed in a
secure manner. As vold is configured to access these temporary files
with root privileges, it may be possible to manipulate vold into creating
or over-writing arbitrary files on the system.

This vulnerability requires that vold be running and media managed by
vold, such as a CDROM or floppy, be physically loaded into a drive. Note
that a local user need not have physical access to the media drive to
exploit this vulnerability. It is enough to wait until somebody else
loads the drive, exploiting the vulnerability at that time.

This vulnerability is known to be present in Solaris 2.4 and Solaris 2.5.
Solaris distributions prior to Solaris 2.4 are also expected to be
vulnerable.

2. Impact

Local users may be able to create or over-write arbitrary files on the
system. This can be leveraged to gain root privileges.

3. Workaround

AUSCERT believes the workarounds given in Sections 3.1 or 3.2 will address
this vulnerability. Vendor patches may also address this vulnerability
in the future (Section 3.3).

3.1 Edit /etc/rmmount.conf

The temporary files which are susceptible to attack are created by the
/usr/lib/rmmount/action_filemgr.so.1 shared object which is called
indirectly by vold through rmmount(1M). rmmount(1M) can be
configured so that it does not create the temporary files, thereby
removing this vulnerability.

To our knowledge, configuring rmmount(1M) in this fashion will not
affect the functionality of vold. It will, however, remove the
ability of the Openwindows File Manager, filemgr(1), to automatically
detect newly mounted media.

To prevent rmmount(1M) creating temporary files, sites must edit the
/etc/rmmount.conf file and comment out (or remove) any entry which
references action_filemgr.so.

The standard /etc/rmmount.conf contains the following entries which
must be commented out (or deleted) to remove this vulnerability:

action cdrom action_filemgr.so
action floppy action_filemgr.so

After applying this workaround, an example of /etc/rmmount.conf may look
like:

# @(#)rmmount.conf 1.2 92/09/23 SMI
#
# Removable Media Mounter configuration file.
#

# File system identification
ident hsfs ident_hsfs.so cdrom
ident ufs ident_ufs.so cdrom floppy pcmem
ident pcfs ident_pcfs.so floppy pcmem

# Actions
#
# Following two lines commented out to remove vold vulnerability
#
# action cdrom action_filemgr.so
# action floppy action_filemgr.so


Note that vold does not have to be restarted for these changes to
take effect.


3.2 Remove the Volume Management system

Sites who do not require the vold functionality should remove the complete
set of Volume Management packages. These are SUNWvolg, SUNWvolu and
SUNWvolr. These packages can be removed using pkgrm(1M).

3.3 Install vendor patches

Currently, AUSCERT is not aware of any official patches which address
this vulnerability. When official patches are made available, AUSCERT
suggests that they be installed.

- -----------------------------------------------------------------------------
AUSCERT wishes to thanks to Leif Hedstrom, Mark McPherson(QTAC),
Marek Krawus(UQ), DFN-CERT and CERT/CC for their assistance in this matter.
- -----------------------------------------------------------------------------

The AUSCERT team have made every effort to ensure that the information
contained in this document is accurate. However, the decision to use the
information described is the responsibility of each user or organisation.
The appropriateness of this document for an organisation or individual system
should be considered before application in conjunction with local policies
and procedures. AUSCERT takes no responsibility for the consequences of
applying the contents of this document.

If you believe that your system has been compromised, contact AUSCERT or your
representative in FIRST (Forum of Incident Response and Security Teams).

AUSCERT is located at The University of Queensland within the Prentice Centre.
AUSCERT is a full member of the Forum of Incident Response and Security Teams
(FIRST).

AUSCERT maintains an anonymous FTP service which is found on:
ftp://ftp.auscert.org.au/pub/. This archive contains past SERT and AUSCERT
Advisories, and other computer security information.

AUSCERT also maintains a World Wide Web service which is found on:
http://www.auscert.org.au/.

Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 4477
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AUSCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for emergencies.

Postal:
Australian Computer Emergency Response Team
c/- Prentice Centre
The University of Queensland
Brisbane
Qld. 4072.
AUSTRALIA

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i
Comment: Finger pgp@ftp.auscert.org.au to retrieve AUSCERT's public key

iQCVAwUBMgH9oih9+71yA2DNAQEdjAP/eulWiaLUYWzOHR3DCh+bJAwwI6sStOaZ
FK4Ef4aiApniXXigsp/L64wkH1X/xo8/+qB/vefihza4ds/KaFI/MaSA0rmKKGmQ
aoJGFrcfwdMVnDjVbrARnWkelY2r7Ms9oHoxAXrOF18r9UjcoIpm4hdoTbJBY+mb
OAJYMd1O890=
=maqr
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    38 Files
  • 24
    Sep 24th
    65 Files
  • 25
    Sep 25th
    24 Files
  • 26
    Sep 26th
    26 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close