Multiple Vendor rlogin Vulnerability
BID:242
Info
Multiple Vendor rlogin Vulnerability
| Bugtraq ID: | 242 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 04 1996 12:00AM |
| Updated: | Dec 04 1996 12:00AM |
| Credit: | This vulnerability was originally posted to the Bugtraq mailing list by Roger Espel Llima <[email protected]> Wed, 4 Dec 1996. A series of vendor and FIRST advisories followed. |
| Vulnerable: |
Sun SunOS 4.1.4 Sun SunOS 4.1.3 _U1 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 NeXT NeXTstep 4.0 NeXT NeXTstep 3.3 NeXT NeXTstep 3.2 NeXT NeXTstep 3.1 NeXT NeXTstep 3.0 NeXT NeXTstep 2.1 NeXT NeXTstep 2.0 NeXT NeXTstep 1.0 a NeXT NeXTstep 1.0 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 3.2 HP HP-UX (VVOS) 10.24 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 HP HP-UX 10.9 HP HP-UX 10.8 HP HP-UX 10.1 0 HP HP-UX 10.0 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 Digital UNIX 4.0 B Digital UNIX 4.0 A Digital UNIX 4.0 Digital UNIX 3.2 G Digital Ultrix 4.5 Digital Ultrix 4.4 Digital Ultrix 4.3 a Digital Ultrix 4.3 Digital Ultrix 4.2 Digital Ultrix 4.1 Digital Ultrix 4.0 Digital Ultrix 3.0 Digital Ultrix 2.2 Debian Linux 0.93 Data General DG/UX 4.0 Data General DG/UX 3.0 Data General DG/UX 2.0 Data General DG/UX 1.0 BSDI BSD/OS 2.1 BSDI BSD/OS 2.0.1 BSDI BSD/OS 2.0 BSDI BSD/OS 1.1 |
| Not Vulnerable: |
Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.4 NeXT NeXTstep 4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2 IBM AIX 4.2 HP HP-UX 11.0 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 Digital UNIX 4.0 D Digital UNIX 4.0 C Data General DG/UX 8.0 Data General DG/UX 7.0 Data General DG/UX 6.0 Data General DG/UX 5.0 BSDI BSD/OS 4.0 BSDI BSD/OS 3.0 |
Discussion
Multiple Vendor rlogin Vulnerability
The SUID rlogin program is used to establish remote sessions. A buffer overflow condition has been found in the rlogin program that may allow an unauthorized user to gain root access. The overflow in particular is in the rlogin code that handles the TERM enviroment variable. Similar bugs have been known to exist in some telnetd implementations.
NOTE:
The vulnerability was updated august 2, 2000 to reflect certain versions of IRIX to be vulnerable.
The SUID rlogin program is used to establish remote sessions. A buffer overflow condition has been found in the rlogin program that may allow an unauthorized user to gain root access. The overflow in particular is in the rlogin code that handles the TERM enviroment variable. Similar bugs have been known to exist in some telnetd implementations.
NOTE:
The vulnerability was updated august 2, 2000 to reflect certain versions of IRIX to be vulnerable.
Solution / Fix
Multiple Vendor rlogin Vulnerability
Solution:
Solutions for various vendors are supplied in the attached vendor and FIRST advisories. Please see the Credit section of thos entry.
Solution:
Solutions for various vendors are supplied in the attached vendor and FIRST advisories. Please see the Credit section of thos entry.
References
Multiple Vendor rlogin Vulnerability
References:
References:
- CERT Coordination Center (CERT/CC)
- HP Electronic Support Center for Europe (Hewlett Packard)
- HP Electronic Support Center for US, Canada, Asia-Pacific, & Latin-America (Hewlett Packard)
- IBM Support Databases (IBM)
- Sun Patch Access Page (Sun Microsystems)
- Sun Patches List (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)