Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
BID:5082
Info
Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
| Bugtraq ID: | 5082 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0677 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Ricardo Quesada of CORE Security Technologies. |
| Vulnerable: |
Xi Graphics DeXtop 2.1 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 IBM AIX 4.3.3 IBM AIX 5.1 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.24 HP HP-UX 10.20 HP HP-UX 10.10 Compaq Tru64 5.1 a Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 4.0 g Compaq Tru64 4.0 f Caldera UnixWare 7.1.1 Caldera UnixWare 7.1 .0 Caldera UnixWare 7 Caldera OpenUnix 8.0 |
| Not Vulnerable: |
SCO Open Server 5.0.6 a SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 Fujitsu UXP/V V10L20 Fujitsu UXP/V V10L10 Caldera OpenLinux 3.1 -IA64 Caldera OpenLinux 2.4 Caldera OpenLinux 2.3 Caldera OpenLinux 2.2 Caldera OpenLinux 1.3 |
Discussion
Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
CDE ships with a daemon called the ToolTalk database server. The ToolTalk database server allows for programs designed for use in CDE to communicate with each other. It is enabled by default on most systems shipped with CDE.
The ToolTalk database server is vulnerable to a condition that may allow for NULL words to be written to arbitrary locations in memory. The vulnerability is due to an input validation error in the _TT_ISCLOSE procedure, used by ToolTalk clients to close open ToolTalk databases.
The _TT_ISCLOSE RPC accepts as a parameter a file descriptor. This integer value is used as an index for writing to structures in server memory. There are no checks to restrict the range of the idnex value. Consequently, malicious file descriptor values supplied by remote clients may cause writes to occur far beyond the table in memory. The only value written is a NULL word, limiting the consequences.
Unfortunately there are several other conditions which may allow for complex attacks, potentially resulting in remote deletion/creation of files and code/command execution.
It should be noted that the only authentication required is client-supplied AUTH_UNIX credentials. AUTH_UNIX credentials may be trivially spoofed by attackers.
CDE ships with a daemon called the ToolTalk database server. The ToolTalk database server allows for programs designed for use in CDE to communicate with each other. It is enabled by default on most systems shipped with CDE.
The ToolTalk database server is vulnerable to a condition that may allow for NULL words to be written to arbitrary locations in memory. The vulnerability is due to an input validation error in the _TT_ISCLOSE procedure, used by ToolTalk clients to close open ToolTalk databases.
The _TT_ISCLOSE RPC accepts as a parameter a file descriptor. This integer value is used as an index for writing to structures in server memory. There are no checks to restrict the range of the idnex value. Consequently, malicious file descriptor values supplied by remote clients may cause writes to occur far beyond the table in memory. The only value written is a NULL word, limiting the consequences.
Unfortunately there are several other conditions which may allow for complex attacks, potentially resulting in remote deletion/creation of files and code/command execution.
It should be noted that the only authentication required is client-supplied AUTH_UNIX credentials. AUTH_UNIX credentials may be trivially spoofed by attackers.
Exploit / POC
Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
Solution:
HP has stated that HP-MPE/ix HP OpenVMS HP NonStop Servers are not vulnerable to this issue. HP has also revised an advisory with fix information. Users running HP-UX 10.10 are advised to contact [email protected] for fix information.
Compaq Computer Corporation
CROSS REFERENCE: SSRT2251
At this time Compaq does have solutions in final testing and will publish HP Tru64 UNIX security bulletin (SSRT2251) with patch information as soon as testing has completed and kits are available from the support ftp web site.
Cray, Inc.
Cray, Inc. does include ToolTalk within the CrayTools product. However, rpc.ttdbserverd is not turned on or used by any Cray provided application. Since a site may have turned this on for their own use, they can always remove the binary /opt/ctl/bin/rpc.ttdbserverd if they are concerned.
IBM Corporation
The CDE desktop product shipped with AIX is vulnerable to both the issues detailed above in the advisory. Fixes have been made available.
Sun Microsystems, Inc.
The Solaris RPC-based ToolTalk database server, rpc.ttdbserverd, is vulnerable to the two vulnerabilities [VU#975403 VU#299816] described in this advisory in all currently supported versions of Solaris:
Solaris 2.5.1, 2.6, 7, 8, and 9
Patches are being generated for all of the above releases. Sun will publish a Sun Security Bulletin and a Sun Alert for this issue. The Sun Alert will be available from:
http://sunsolve.sun.com
The patches will be available from:
http://sunsolve.sun.com/securitypatch
Sun Security Bulletins are available from:
http://sunsolve.sun.com/security
Xi Graphics
Xi Graphics deXtop CDE v2.1 is vulnerable to this attack. A update correcting this issue will be available on our ftp site once this vulnerability has been publicly announced.
When announced, the update and accompanying text file will be:
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.txt
SGI has released a new advisory. A new patch, 4669, is available for IRIX 6.5.13 to 6.5.17.
Sun has released Sun Alert ID: 46022 dealing with this and other issues. Please see the referenced advisory for more information.
Sun Solaris 8_sparc
IBM AIX 5.1
Sun Solaris 2.6
Sun Solaris 2.6_x86
Sun Solaris 7.0
Sun Solaris 9
Sun Solaris 7.0_x86
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX 10.24
HP HP-UX 11.0
HP HP-UX 11.11
IBM AIX 4.3.3
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 m
SGI IRIX 6.5.10 f
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14
SGI IRIX 6.5.14 m
SGI IRIX 6.5.15
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.2
SGI IRIX 6.5.3 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 f
SGI IRIX 6.5.5 m
SGI IRIX 6.5.6
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Solution:
HP has stated that HP-MPE/ix HP OpenVMS HP NonStop Servers are not vulnerable to this issue. HP has also revised an advisory with fix information. Users running HP-UX 10.10 are advised to contact [email protected] for fix information.
Compaq Computer Corporation
CROSS REFERENCE: SSRT2251
At this time Compaq does have solutions in final testing and will publish HP Tru64 UNIX security bulletin (SSRT2251) with patch information as soon as testing has completed and kits are available from the support ftp web site.
Cray, Inc.
Cray, Inc. does include ToolTalk within the CrayTools product. However, rpc.ttdbserverd is not turned on or used by any Cray provided application. Since a site may have turned this on for their own use, they can always remove the binary /opt/ctl/bin/rpc.ttdbserverd if they are concerned.
IBM Corporation
The CDE desktop product shipped with AIX is vulnerable to both the issues detailed above in the advisory. Fixes have been made available.
Sun Microsystems, Inc.
The Solaris RPC-based ToolTalk database server, rpc.ttdbserverd, is vulnerable to the two vulnerabilities [VU#975403 VU#299816] described in this advisory in all currently supported versions of Solaris:
Solaris 2.5.1, 2.6, 7, 8, and 9
Patches are being generated for all of the above releases. Sun will publish a Sun Security Bulletin and a Sun Alert for this issue. The Sun Alert will be available from:
http://sunsolve.sun.com
The patches will be available from:
http://sunsolve.sun.com/securitypatch
Sun Security Bulletins are available from:
http://sunsolve.sun.com/security
Xi Graphics
Xi Graphics deXtop CDE v2.1 is vulnerable to this attack. A update correcting this issue will be available on our ftp site once this vulnerability has been publicly announced.
When announced, the update and accompanying text file will be:
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.txt
SGI has released a new advisory. A new patch, 4669, is available for IRIX 6.5.13 to 6.5.17.
Sun has released Sun Alert ID: 46022 dealing with this and other issues. Please see the referenced advisory for more information.
Sun Solaris 8_sparc
-
Sun 110286-09
http://sunsolve.sun.com
IBM AIX 5.1
-
IBM IY32370
http://www.ibm.com/support
Sun Solaris 2.6
-
Sun 105802-18
http://sunsolve.sun.com
Sun Solaris 2.6_x86
-
Sun 105803-20
http://sunsolve.sun.com
Sun Solaris 7.0
-
Sun 107893-19
http://sunsolve.sun.com
Sun Solaris 9
-
Sun 112808-02
http://sunsolve.sun.com
Sun Solaris 7.0_x86
-
Sun 107894-19
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 110287-09
http://sunsolve.sun.com
HP HP-UX 10.10
-
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 10.20
-
HP PHSS_27426
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 10.24
-
HP PHSS_28173
http://itrc.hp.com
HP HP-UX 11.0
-
HP PHSS_27427
http://itrc.hp.com -
HP PHSS_27869
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 11.11
-
HP PHSS_27428
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
IBM AIX 4.3.3
-
IBM IY32368
http://www.ibm.com/support
SGI IRIX 6.5
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.1
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9
-
SGI 4799
http://patches.sgi.com
Caldera UnixWare 7.1.1
-
Caldera erg711831b.Z
ftp://ftp.caldera.com/pub/updates/UnixWare/CSSA-2001-SCO.28/erg711831b .Z
Caldera OpenUnix 8.0
-
Caldera erg712073.pkg.Z
ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.28/erg712073. pkg.Z