Gauntlet Firewall Remote Buffer Overflow Vulnerability
BID:1234
Info
Gauntlet Firewall Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 1234 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0437 CVE-2004-0999 |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | This vulnerability was discovered by Jim Stickley, with Garrison Technologies, and was reported to SecurityFocus.com on May 19, 2000. |
| Vulnerable: |
SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 Network Associates WebShield for Solaris 4.0 Network Associates WebShield E-ppliance 300.0 Network Associates WebShield E-ppliance 100.0 Network Associates Gauntlet Firewall 5.5 Network Associates Gauntlet Firewall 5.0 Network Associates Gauntlet Firewall 4.2 Network Associates Gauntlet Firewall 4.1 |
| Not Vulnerable: | |
Discussion
Gauntlet Firewall Remote Buffer Overflow Vulnerability
A buffer overflow exists in the version of Mattel's Cyber Patrol software integrated in to Network Associates Gauntlet firewall, versions 4.1, 4.2, 5.0 and 5.5. Due to the manner in which Cyber Patrol was integrated, a vulnerability was introduced which could allow a remote attacker to gain root access on the firewall, or execute arbitrary commands on the firewall.
By default, Cyber Patrol is installed on Gauntlet installations, and runs for 30 days. After that period, it is disabled. During this 30 day period, the firewall is susceptible to attack,. Due to the filtering software being externally accessible, users not on the internal network may also be able to exploit the vulnerability.
Some versions of SGI IRIX shipped with the Gauntlet Firewall package, and in the past it was a supported SGI product. While it is no longer being supported, SGI IRIX versions 6.5.2, 6.5.3, 6.5.4 and 6.5.5 may be prone to this issue.
A buffer overflow exists in the version of Mattel's Cyber Patrol software integrated in to Network Associates Gauntlet firewall, versions 4.1, 4.2, 5.0 and 5.5. Due to the manner in which Cyber Patrol was integrated, a vulnerability was introduced which could allow a remote attacker to gain root access on the firewall, or execute arbitrary commands on the firewall.
By default, Cyber Patrol is installed on Gauntlet installations, and runs for 30 days. After that period, it is disabled. During this 30 day period, the firewall is susceptible to attack,. Due to the filtering software being externally accessible, users not on the internal network may also be able to exploit the vulnerability.
Some versions of SGI IRIX shipped with the Gauntlet Firewall package, and in the past it was a supported SGI product. While it is no longer being supported, SGI IRIX versions 6.5.2, 6.5.3, 6.5.4 and 6.5.5 may be prone to this issue.
Exploit / POC
Gauntlet Firewall Remote Buffer Overflow Vulnerability
This exploit is written to run a test file called /bin/zz. Just throw a file called zz in /bin on the gauntlet firewall and chmod it to 700. Inside the zz file you should have it do something where it will leave you a log, as in the following example:
---
#!/bin/sh
echo "IT RAN" > /tmp/TEST
---
This exploit is written to run a test file called /bin/zz. Just throw a file called zz in /bin on the gauntlet firewall and chmod it to 700. Inside the zz file you should have it do something where it will leave you a log, as in the following example:
---
#!/bin/sh
echo "IT RAN" > /tmp/TEST
---
Solution / Fix
Gauntlet Firewall Remote Buffer Overflow Vulnerability
Solution:
Patches from NAI are available.
Network Associates WebShield E-ppliance 100.0
Network Associates WebShield E-ppliance 300.0
Network Associates WebShield for Solaris 4.0
Network Associates Gauntlet Firewall 4.1
Network Associates Gauntlet Firewall 4.2
Network Associates Gauntlet Firewall 5.0
Network Associates Gauntlet Firewall 5.5
Solution:
Patches from NAI are available.
Network Associates WebShield E-ppliance 100.0
-
NAI WebShield 100 cyber.patch
http://download.nai.com/products/patches/WebShield/W100/cyber.patch
Network Associates WebShield E-ppliance 300.0
-
NAI WebShield 300 cyber.patch
http://download.nai.com/products/patches/WebShield/W300/cyber.patch
Network Associates WebShield for Solaris 4.0
-
NAI WS4.0 cyber.patch
http://download.nai.com/products/patches/WebShield/Wfs40/cyber.patch
Network Associates Gauntlet Firewall 4.1
-
NAI Gauntlet Firewall for Unix and WebShield cyberdaemon Buffer Overflow Vulnerability Advisory
http://www.tis.com/support/cyberadvisory.html
Network Associates Gauntlet Firewall 4.2
-
NAI Gauntlet 4.2 cyber.patch
http://download.nai.com/products/patches/gauntlet/4.2/cyber.patch -
NAI Gauntlet Firewall for Unix and WebShield cyberdaemon Buffer Overflow Vulnerability Advisory
http://www.tis.com/support/cyberadvisory.html
Network Associates Gauntlet Firewall 5.0
-
NAI Gauntlet 5.0 cyber.patch
http://download.nai.com/products/patches/gauntlet/5.0/cyber.patch -
NAI Gauntlet Firewall for Unix and WebShield cyberdaemon Buffer Overflow Vulnerability Advisory
http://www.tis.com/support/cyberadvisory.html
Network Associates Gauntlet Firewall 5.5
-
NAI Gauntlet 5.5 cyber.patch
http://download.nai.com/products/patches/gauntlet/5.5/cyber.patch -
NAI Gauntlet Firewall for Unix and WebShield cyberdaemon Buffer Overflow Vulnerability Advisory
http://www.tis.com/support/cyberadvisory.html
References
Gauntlet Firewall Remote Buffer Overflow Vulnerability
References:
References:
- Gauntlet Advisory and Patches (COVERT Research Center)
- Gauntlet Support: Gauntlet Firewall for Unix and WebShield cyberdaemon Buffer Ov (TIS)