Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
BID:3382
Info
Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
| Bugtraq ID: | 3382 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0717 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2001 12:00AM |
| Updated: | Apr 18 2006 11:36PM |
| Credit: | Discovered by ISS X-Force. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 IBM AIX 4.3.3 IBM AIX 4.3.2 IBM AIX 4.3.1 IBM AIX 4.3 IBM AIX 5.1 HP HP-UX (VVOS) 11.0 4 HP HP-UX (VVOS) 10.24 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.10 Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 4.0 g Compaq Digital Unix 4.0 f Caldera UnixWare 7 Caldera OpenUnix 8.0 |
| Not Vulnerable: |
SGI IRIX 6.5.19 SGI IRIX 6.5.18 |
Discussion
Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
CDE ships with a daemon called the ToolTalk database server, which allows programs designed for use in CDE to communicate with each other. The server is enabled by default on most systems shipped with CDE.
ToolTalk database server contains a remotely exploitable format-string vulnerability.
Remote attackers may be able to cause a denial of service or gain root access on the target host.
CDE ships with a daemon called the ToolTalk database server, which allows programs designed for use in CDE to communicate with each other. The server is enabled by default on most systems shipped with CDE.
ToolTalk database server contains a remotely exploitable format-string vulnerability.
Remote attackers may be able to cause a denial of service or gain root access on the target host.
Exploit / POC
Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
Solution:
Administrators are highly advised to disable the service until fixes are available. This may involve renaming/removing the startup script in the appropriate directory. Administrators should also ensure that the service is not running and should kill the process if it is.
HP has released fixes for some versions of HP-UX.
IBM has released a temporary hotfix.
Compaq has released fixes for Digital Unix/Tru64.
Sun has released fixes.
Caldera has released a fix for OpenUnix and Unixware.
SGI has released an updated advisory (Security Bulletin 20021102-02-P) and fixes that address an issue discovered in the fixes found in Security Bulletin 20021102-01-P.
Sun Solaris 2.5_x86
Caldera UnixWare 7
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
Sun Solaris 2.5
Sun Solaris 7.0
IBM AIX 5.1
Sun Solaris 7.0_x86
Sun Solaris 2.6
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0 4
HP HP-UX 11.11
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _x86
Compaq Tru64 4.0 g
Compaq Digital Unix 4.0 f
IBM AIX 4.3
IBM AIX 4.3.1
IBM AIX 4.3.2
IBM AIX 4.3.3
Compaq Tru64 5.0 a
Compaq Tru64 5.1
SGI IRIX 6.5.13
SGI IRIX 6.5.14
SGI IRIX 6.5.15
SGI IRIX 6.5.16
SGI IRIX 6.5.17
Caldera OpenUnix 8.0
Solution:
Administrators are highly advised to disable the service until fixes are available. This may involve renaming/removing the startup script in the appropriate directory. Administrators should also ensure that the service is not running and should kill the process if it is.
HP has released fixes for some versions of HP-UX.
IBM has released a temporary hotfix.
Compaq has released fixes for Digital Unix/Tru64.
Sun has released fixes.
Caldera has released a fix for OpenUnix and Unixware.
SGI has released an updated advisory (Security Bulletin 20021102-02-P) and fixes that address an issue discovered in the fixes found in Security Bulletin 20021102-01-P.
Sun Solaris 2.5_x86
Caldera UnixWare 7
-
Caldera erg711831.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/erg7118 31.Z
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
Sun Solaris 2.5
Sun Solaris 7.0
IBM AIX 5.1
-
IBM tooltalk_efix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/tooltalk_efix.tar.Z -
IBM IY23846
http://www.ibm.com
Sun Solaris 7.0_x86
Sun Solaris 2.6
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0 4
HP HP-UX 11.11
-
HP PHSS_25139
-
HP PHSS_27428
http://itrc.hp.com
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _x86
Compaq Tru64 4.0 g
Compaq Digital Unix 4.0 f
IBM AIX 4.3
-
IBM tooltalk_efix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/tooltalk_efix.tar.Z -
IBM IY24387
http://www.ibm.com
IBM AIX 4.3.1
-
IBM tooltalk_efix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/tooltalk_efix.tar.Z -
IBM IY24387
http://www.ibm.com
IBM AIX 4.3.2
-
IBM tooltalk_efix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/tooltalk_efix.tar.Z -
IBM IY24387
http://www.ibm.com
IBM AIX 4.3.3
-
IBM tooltalk_efix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/tooltalk_efix.tar.Z -
IBM IY24387
http://www.ibm.com
Compaq Tru64 5.0 a
Compaq Tru64 5.1
SGI IRIX 6.5.13
-
SGI 4869
ftp://patches.sgi.com/
SGI IRIX 6.5.14
-
SGI 4869
ftp://patches.sgi.com/
SGI IRIX 6.5.15
-
SGI 4869
ftp://patches.sgi.com/
SGI IRIX 6.5.16
-
SGI 4869
ftp://patches.sgi.com/
SGI IRIX 6.5.17
-
SGI 4869
ftp://patches.sgi.com/
Caldera OpenUnix 8.0
-
Caldera erg711831.Z
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/erg7118 31.Z
References
Multiple CDE Vendor ToolTalk Database Server Format String Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- Caldera Security Advisories Page (Caldera Systems)
- HP IT Resource Center (for Europe) (HP IT Resource Center)
- HP IT Resource Center (for US, Canada, Asia-Pacific, & Latin-America) (HP IT Resource Center)
- IBM Emergency Response Service (IBM)
- SGI Support (Silicon Graphics Inc.)
- Sun Patch Access Page (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)
- Tru64 Homepage (Compaq)
- ttdbserverd format string exploit (CORE Security)