OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
BID:27172
Info
OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
| Bugtraq ID: | 27172 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0003 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2008 12:00AM |
| Updated: | Feb 12 2009 03:48PM |
| Credit: | Roger Kumpf discovered this issue. |
| Vulnerable: |
VMWare ESX Server 3.5 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4.5.z RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Fedora 8 Red Hat Fedora 7 Red Hat Enterprise Linux AS 4.5.z Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server OpenPegasus OpenPegasus 2.6.1 IBM Pegasus CIM Server 2.6.1 IBM Pegasus CIM Server 2.5.1 HP WBEM A.02.07 HP WBEM A.02.05.08 HP HP-UX B.11.31 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Avaya Message Networking MN 3.1 Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: | |
Discussion
OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
OpenPegasus is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
This issue occurs in the PAM (Pluggable Authentication Module) authentication code.
Attackers can leverage this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
Versions in the OpenPegasus 2.6 series are vulnerable.
OpenPegasus is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
This issue occurs in the PAM (Pluggable Authentication Module) authentication code.
Attackers can leverage this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
Versions in the OpenPegasus 2.6 series are vulnerable.
Exploit / POC
OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
Solution:
Fixes are available. Please see the references for more information.
VMWare ESX Server 3.5
IBM Pegasus CIM Server 2.5.1
IBM Pegasus CIM Server 2.6.1
Solution:
Fixes are available. Please see the references for more information.
VMWare ESX Server 3.5
-
VMWare ESX350-200803201-UG
http://download3.vmware.com/software/esx/ESX350-200803201-UG.zip
IBM Pegasus CIM Server 2.5.1
-
IBM pegasus_ifix.tar
ftp://aix.software.ibm.com/aix/efixes/security/pegasus_ifix.tar
IBM Pegasus CIM Server 2.6.1
-
IBM pegasus_ifix.tar
ftp://aix.software.ibm.com/aix/efixes/security/pegasus_ifix.tar
References
OpenPegasus WBEM CIM Management Server 'PAMBasicAuthenticatorUnix.cpp' Buffer Overflow Vulnerability
References:
References:
- Bugzilla Bug 426578: CVE-2008-0003 tog-pegasus pam authentication buffer overfl (Red Hat)
- CVS BUG#:7220
Memory error in PAM module (Roger Kumpf) - Diff for /pegasus/src/Pegasus/Security/Authentication/PAMBasicAuthenticatorUnix. (OpenPegasus)
- Vendor Homepage (OpenPegasus)
- [security bulletin] HPSBMA02331 SSRT080000 rev.1 - HP-UX running WBEM Services, ([email protected])
- ASA-2008-028 tog-pegasus security update (RHSA-2008-0002) (Avaya)
- RHSA-2008:0002-7 Critical: tog-pegasus security update (Red Hat)