Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
BID:4126
Info
Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
| Bugtraq ID: | 4126 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 18 2002 12:00AM |
| Updated: | Feb 18 2002 12:00AM |
| Credit: | Details published by Caldera Systems. |
| Vulnerable: |
Caldera UnixWare 7.1.1 Caldera UnixWare 7.1 .0 Caldera UnixWare 7 Caldera OpenUnix 8.0 Caldera Open Server 7.0 |
| Not Vulnerable: | |
Discussion
Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
Calera produces a variety of Linux and Unix based operating systems, including Open Unix, UnixWare and Open Server.
A vulnerability has been reported in the default installation of some versions of UnixWare and Open Unix. Files exist which are world readable and include the encrypted root password. A local user would be able to access this information, and may be able to mount a dictionary attack on the root password without detection.
It is not currently known if this file reflects the current state of a changed root password.
Calera produces a variety of Linux and Unix based operating systems, including Open Unix, UnixWare and Open Server.
A vulnerability has been reported in the default installation of some versions of UnixWare and Open Unix. Files exist which are world readable and include the encrypted root password. A local user would be able to access this information, and may be able to mount a dictionary attack on the root password without detection.
It is not currently known if this file reflects the current state of a changed root password.
Exploit / POC
Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
Solution:
Caldera has suggsted changing the permissions of affected files to allow only root access (mode 400):
UnixWare 7
/usr/ns-home/admserv/admpw
/usr/internet/httpd/admserv/admpw
Open UNIX 8.0.0
/usr/ns-home/admserv/admpw
/usr/internet/httpd/admserv/admpw
/var/sadm/pkg/update800/install/morepkgs/scripts/debug.out
OpenServer
/var/opt/K/SCO/link/*/.softmgmt/ccsPersistent/cqs.save.file
/var/opt/K/SCO/Vidconf/*/.softmgmt/ccsPersistent/iqm_file
Caldera also suggests that the root and owner passwords be changed.
Furthermore, the integrity of the system should be checked to ensure that compromise of root access has not already occured.
Solution:
Caldera has suggsted changing the permissions of affected files to allow only root access (mode 400):
UnixWare 7
/usr/ns-home/admserv/admpw
/usr/internet/httpd/admserv/admpw
Open UNIX 8.0.0
/usr/ns-home/admserv/admpw
/usr/internet/httpd/admserv/admpw
/var/sadm/pkg/update800/install/morepkgs/scripts/debug.out
OpenServer
/var/opt/K/SCO/link/*/.softmgmt/ccsPersistent/cqs.save.file
/var/opt/K/SCO/Vidconf/*/.softmgmt/ccsPersistent/iqm_file
Caldera also suggests that the root and owner passwords be changed.
Furthermore, the integrity of the system should be checked to ensure that compromise of root access has not already occured.
References
Multiple Caldera Encrypted root Password Local Disclosure Vulnerability
References:
References: