TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
BID:10967
Info
TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
| Bugtraq ID: | 10967 |
| Class: | Race Condition Error |
| CVE: |
CVE-2004-0794 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Przemyslaw Frasunek disclosed these vulnerabilities. |
| Vulnerable: |
Sun Java Desktop System (JDS) 2.0 Sun Java Desktop System (JDS) 2003 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 sh3 NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.4 SPARC NetBSD NetBSD 1.4 arm32 NetBSD NetBSD 1.4 Alpha NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD Current Luke Mewburn TNFTPD 20031217 Luke Mewburn lukemftp 1.5 Luke Mewburn lukemftp 1.1 Heimdal Heimdal 0.6.2 Heimdal Heimdal 0.6.1 Heimdal Heimdal 0.6 Heimdal Heimdal 0.5.3 Heimdal Heimdal 0.5.2 Heimdal Heimdal 0.5.1 Heimdal Heimdal 0.5 .0 Heimdal Heimdal 0.4 e Heimdal Heimdal 0.4 d Heimdal Heimdal 0.4 c Heimdal Heimdal 0.4 b Heimdal Heimdal 0.4 a Heimdal Heimdal 0.3 f Gentoo Linux 1.4 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.2.8 |
| Not Vulnerable: |
Luke Mewburn TNFTPD 20040810 Heimdal Heimdal 0.6.3 |
Discussion
TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
It is reported that TNFTPD is susceptible to multiple remote superuser compromise vulnerabilities. These vulnerabilities are all derived from improper signal handler operations. Signals can be delivered to the vulnerable FTPD by a remote attacker via out-of-band TCP data (OOB).
These vulnerabilities may allow an anonymous remote attacker to gain superuser privileges on computer hosting the affected software.
TNFTPD versions prior to 10 Aug 2004 are reported vulnerable. All versions of Lukemftpd are reported vulnerable. NetBSD version 1.6.2 and prior, NetBSD-2.0 prior to 15 Aug 2004, as well as NetBSD-current prior to 10 Aug 2004 are reported vulnerable as well.
It is reported that TNFTPD is susceptible to multiple remote superuser compromise vulnerabilities. These vulnerabilities are all derived from improper signal handler operations. Signals can be delivered to the vulnerable FTPD by a remote attacker via out-of-band TCP data (OOB).
These vulnerabilities may allow an anonymous remote attacker to gain superuser privileges on computer hosting the affected software.
TNFTPD versions prior to 10 Aug 2004 are reported vulnerable. All versions of Lukemftpd are reported vulnerable. NetBSD version 1.6.2 and prior, NetBSD-2.0 prior to 15 Aug 2004, as well as NetBSD-current prior to 10 Aug 2004 are reported vulnerable as well.
Exploit / POC
TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
Solution:
The vendor has released patches resolving these issues.
NetBSD has released advisory 2004-009 addressing this issue. Please see the referenced advisory for further information. Fixes are available from CVS for the NetBSD-current and NetBSD-2.0 branches.
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Heimdal has released an advisory (2004-09-13) along with version 0.6.3 to address this issue. Please see the referenced advisory for further information.
Gentoo Linux has released an advisory (GLSA 200409-19) to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=app-crypt/heimdal-0.6.3"
emerge ">=app-crypt/heimdal-0.6.3"
Debian Linux has released an advisory (DSA 551-1) along with fixes dealing with this issue. Please the referenced advisory for more information.
Sun has released an advisory (Sun Alert ID: 57655) with fixes to address these issues in Sun Java Desktop System (JDS) 2003 and Release 2 for the Linux platform. Please see the advisory in Web references for more information. Users may carry out the following actions from the launch bar to download the patch:
Launch >> Applications >> System Tools >> Online Update
Luke Mewburn TNFTPD 20031217
Sun Java Desktop System (JDS) 2003
Heimdal Heimdal 0.3 f
Heimdal Heimdal 0.4 b
Heimdal Heimdal 0.4 d
Heimdal Heimdal 0.4 c
Heimdal Heimdal 0.4 a
Heimdal Heimdal 0.4 e
Heimdal Heimdal 0.5 .0
Heimdal Heimdal 0.5.1
Heimdal Heimdal 0.5.2
Heimdal Heimdal 0.5.3
Heimdal Heimdal 0.6
Heimdal Heimdal 0.6.1
Heimdal Heimdal 0.6.2
Luke Mewburn lukemftp 1.1
Luke Mewburn lukemftp 1.5
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
Sun Java Desktop System (JDS) 2.0
Solution:
The vendor has released patches resolving these issues.
NetBSD has released advisory 2004-009 addressing this issue. Please see the referenced advisory for further information. Fixes are available from CVS for the NetBSD-current and NetBSD-2.0 branches.
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Heimdal has released an advisory (2004-09-13) along with version 0.6.3 to address this issue. Please see the referenced advisory for further information.
Gentoo Linux has released an advisory (GLSA 200409-19) to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=app-crypt/heimdal-0.6.3"
emerge ">=app-crypt/heimdal-0.6.3"
Debian Linux has released an advisory (DSA 551-1) along with fixes dealing with this issue. Please the referenced advisory for more information.
Sun has released an advisory (Sun Alert ID: 57655) with fixes to address these issues in Sun Java Desktop System (JDS) 2003 and Release 2 for the Linux platform. Please see the advisory in Web references for more information. Users may carry out the following actions from the launch bar to download the patch:
Launch >> Applications >> System Tools >> Online Update
Luke Mewburn TNFTPD 20031217
-
Luke Mewburn tnftpd-20040810.tar.gz
ftp://ftp.netbsd.org/pub/NetBSD/misc/tnftp/tnftpd-20040810.tar.gz
Sun Java Desktop System (JDS) 2003
Heimdal Heimdal 0.3 f
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.4 b
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.4 d
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.4 c
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.4 a
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.4 e
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.5 .0
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.5.1
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.5.2
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.5.3
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.6
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.6.1
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Heimdal Heimdal 0.6.2
-
Heimdal heimdal-0.6.3.tar.gz
ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.3.tar.gz
Luke Mewburn lukemftp 1.1
-
Debian lukemftpd_1.1-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_alpha.deb -
Debian lukemftpd_1.1-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_arm.deb -
Debian lukemftpd_1.1-1woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_hppa.deb -
Debian lukemftpd_1.1-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_i386.deb -
Debian lukemftpd_1.1-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_ia64.deb -
Debian lukemftpd_1.1-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_m68k.deb -
Debian lukemftpd_1.1-1woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_mips.deb -
Debian lukemftpd_1.1-1woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_mipsel.deb -
Debian lukemftpd_1.1-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_powerpc.deb -
Debian lukemftpd_1.1-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_s390.deb -
Debian lukemftpd_1.1-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/lukemftpd/lukemftpd_1.1 -1woody2_sparc.deb
Luke Mewburn lukemftp 1.5
-
Luke Mewburn tnftpd-20040810.tar.gz
ftp://ftp.netbsd.org/pub/NetBSD/misc/tnftp/tnftpd-20040810.tar.gz
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-09-07JagClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04717&plat form=osx&method=sa/SecUpd2004-09-07JagClient.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2004-09-07PanClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04712&plat form=osx&method=sa/SecUpd2004-09-07PanClient.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2004-09-07PanMClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04715&plat form=osx&method=sa/SecUpd2004-09-07PanMClient.dmg
Sun Java Desktop System (JDS) 2.0
References
TNFTPD Multiple Signal Handler Remote Superuser Compromise Vulnerabilities
References:
References:
- 2004-09-13: ftpd root escalation (Heimdal)
- Bugzilla Bug 61412- app-crypt/heimdal ftpd Signal Handling Vulnerabilities (Gentoo)
- Heimdal 0.6.3 (Heimdal)
- Heimdal Home Page (Heimdal)
- Multiple vulnerabilities in lukemftpd/tnftpd (Przemyslaw Frasunek)
- Sun Alert ID: 57655 (Sun)
- TNFTPD Home Page (Luke Mewburn)