Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability

BID:5082

Info

Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability

Bugtraq ID: 5082
Class: Input Validation Error
CVE: CVE-2002-0677
Remote: Yes
Local: No
Published: Jul 11 2002 12:00AM
Updated: Jul 11 2009 01:56PM
Credit: Discovered by Ricardo Quesada of CORE Security Technologies.
Vulnerable: Xi Graphics DeXtop 2.1
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Sun Solaris 9
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.17
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.15
SGI IRIX 6.5.14 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.11
SGI IRIX 6.5.10 m
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8 f
SGI IRIX 6.5.8
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7 f
SGI IRIX 6.5.7
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.5
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4 f
SGI IRIX 6.5.4
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.3
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
SGI IRIX 6.4
SGI IRIX 6.3
SGI IRIX 6.2
SGI IRIX 6.1
SGI IRIX 6.0.1
SGI IRIX 6.0
SGI IRIX 5.3
SGI IRIX 5.2
IBM AIX 4.3.3
IBM AIX 5.1
HP HP-UX 11.11
HP HP-UX 11.0
HP HP-UX 10.24
HP HP-UX 10.20
HP HP-UX 10.10
Compaq Tru64 5.1 a
Compaq Tru64 5.1
Compaq Tru64 5.0 a
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f
Caldera UnixWare 7.1.1
Caldera UnixWare 7.1 .0
Caldera UnixWare 7
Caldera OpenUnix 8.0
Not Vulnerable: SCO Open Server 5.0.6 a
SCO Open Server 5.0.6
SCO Open Server 5.0.5
SCO Open Server 5.0.4
SCO Open Server 5.0.3
SCO Open Server 5.0.2
SCO Open Server 5.0.1
SCO Open Server 5.0
Fujitsu UXP/V V10L20
Fujitsu UXP/V V10L10
Caldera OpenLinux 3.1 -IA64
Caldera OpenLinux 2.4
Caldera OpenLinux 2.3
Caldera OpenLinux 2.2
Caldera OpenLinux 1.3

Discussion

Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability

CDE ships with a daemon called the ToolTalk database server. The ToolTalk database server allows for programs designed for use in CDE to communicate with each other. It is enabled by default on most systems shipped with CDE.

The ToolTalk database server is vulnerable to a condition that may allow for NULL words to be written to arbitrary locations in memory. The vulnerability is due to an input validation error in the _TT_ISCLOSE procedure, used by ToolTalk clients to close open ToolTalk databases.

The _TT_ISCLOSE RPC accepts as a parameter a file descriptor. This integer value is used as an index for writing to structures in server memory. There are no checks to restrict the range of the idnex value. Consequently, malicious file descriptor values supplied by remote clients may cause writes to occur far beyond the table in memory. The only value written is a NULL word, limiting the consequences.

Unfortunately there are several other conditions which may allow for complex attacks, potentially resulting in remote deletion/creation of files and code/command execution.

It should be noted that the only authentication required is client-supplied AUTH_UNIX credentials. AUTH_UNIX credentials may be trivially spoofed by attackers.

Exploit / POC

Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability

Solution:
HP has stated that HP-MPE/ix HP OpenVMS HP NonStop Servers are not vulnerable to this issue. HP has also revised an advisory with fix information. Users running HP-UX 10.10 are advised to contact [email protected] for fix information.

Compaq Computer Corporation

CROSS REFERENCE: SSRT2251

At this time Compaq does have solutions in final testing and will publish HP Tru64 UNIX security bulletin (SSRT2251) with patch information as soon as testing has completed and kits are available from the support ftp web site.

Cray, Inc.

Cray, Inc. does include ToolTalk within the CrayTools product. However, rpc.ttdbserverd is not turned on or used by any Cray provided application. Since a site may have turned this on for their own use, they can always remove the binary /opt/ctl/bin/rpc.ttdbserverd if they are concerned.

IBM Corporation

The CDE desktop product shipped with AIX is vulnerable to both the issues detailed above in the advisory. Fixes have been made available.

Sun Microsystems, Inc.

The Solaris RPC-based ToolTalk database server, rpc.ttdbserverd, is vulnerable to the two vulnerabilities [VU#975403 VU#299816] described in this advisory in all currently supported versions of Solaris:

Solaris 2.5.1, 2.6, 7, 8, and 9

Patches are being generated for all of the above releases. Sun will publish a Sun Security Bulletin and a Sun Alert for this issue. The Sun Alert will be available from:

http://sunsolve.sun.com

The patches will be available from:

http://sunsolve.sun.com/securitypatch

Sun Security Bulletins are available from:

http://sunsolve.sun.com/security

Xi Graphics

Xi Graphics deXtop CDE v2.1 is vulnerable to this attack. A update correcting this issue will be available on our ftp site once this vulnerability has been publicly announced.

When announced, the update and accompanying text file will be:

ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.txt

SGI has released a new advisory. A new patch, 4669, is available for IRIX 6.5.13 to 6.5.17.

Sun has released Sun Alert ID: 46022 dealing with this and other issues. Please see the referenced advisory for more information.


Sun Solaris 8_sparc

IBM AIX 5.1

Sun Solaris 2.6

Sun Solaris 2.6_x86

Sun Solaris 7.0

Sun Solaris 9

Sun Solaris 7.0_x86

Sun Solaris 8_x86

HP HP-UX 10.10
  • HP rpc.ttdbserver
    FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
    ftp://hprc.external.hp.com


HP HP-UX 10.20

HP HP-UX 10.24

HP HP-UX 11.0

HP HP-UX 11.11

IBM AIX 4.3.3

SGI IRIX 6.5

SGI IRIX 6.5.1

SGI IRIX 6.5.10

SGI IRIX 6.5.10 m

SGI IRIX 6.5.10 f

SGI IRIX 6.5.11

SGI IRIX 6.5.11 m

SGI IRIX 6.5.11 f

SGI IRIX 6.5.12 f

SGI IRIX 6.5.12 m

SGI IRIX 6.5.12

SGI IRIX 6.5.13 f

SGI IRIX 6.5.13 m

SGI IRIX 6.5.13

SGI IRIX 6.5.14 f

SGI IRIX 6.5.14

SGI IRIX 6.5.14 m

SGI IRIX 6.5.15

SGI IRIX 6.5.15 m

SGI IRIX 6.5.15 f

SGI IRIX 6.5.16 f

SGI IRIX 6.5.16

SGI IRIX 6.5.16 m

SGI IRIX 6.5.17

SGI IRIX 6.5.17 m

SGI IRIX 6.5.17 f

SGI IRIX 6.5.2 m

SGI IRIX 6.5.2 f

SGI IRIX 6.5.2

SGI IRIX 6.5.3 f

SGI IRIX 6.5.3

SGI IRIX 6.5.3 m

SGI IRIX 6.5.4 m

SGI IRIX 6.5.4

SGI IRIX 6.5.4 f

SGI IRIX 6.5.5

SGI IRIX 6.5.5 f

SGI IRIX 6.5.5 m

SGI IRIX 6.5.6

SGI IRIX 6.5.6 m

SGI IRIX 6.5.6 f

SGI IRIX 6.5.7 m

SGI IRIX 6.5.7

SGI IRIX 6.5.7 f

SGI IRIX 6.5.8 m

SGI IRIX 6.5.8

SGI IRIX 6.5.8 f

SGI IRIX 6.5.9 f

SGI IRIX 6.5.9 m

SGI IRIX 6.5.9

Caldera UnixWare 7.1.1

Caldera OpenUnix 8.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report