Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
BID:5083
Info
Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
| Bugtraq ID: | 5083 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0678 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Ricardo Quesada of CORE Security Technologies. |
| Vulnerable: |
Xi Graphics DeXtop 2.1 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 IBM AIX 4.3.3 IBM AIX 5.1 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.24 HP HP-UX 10.20 HP HP-UX 10.10 Compaq Tru64 5.1 a Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 4.0 g Compaq Tru64 4.0 f Caldera UnixWare 7.1.1 Caldera UnixWare 7.1 .0 Caldera UnixWare 7 Caldera OpenUnix 8.0 |
| Not Vulnerable: |
SCO Open Server 5.0.6 a SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 Fujitsu UXP/V V10L20 Fujitsu UXP/V V10L10 Caldera OpenLinux 3.1 -IA64 Caldera OpenLinux 2.4 Caldera OpenLinux 2.3 Caldera OpenLinux 2.2 Caldera OpenLinux 1.3 |
Discussion
Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
CDE ships with a daemon called the ToolTalk database server. The ToolTalk database server allows for programs designed for use in CDE to communicate with each other. It is enabled by default on most systems shipped with CDE.
The ToolTalk database server is vulnerable to a symbolic link vulnerability that is exploitable by attackers with access to the filesystem.
The server logs transactions to logfiles with filenames based on the name of the ToolTalk database supplied by the client. When writing to the logfile, the server does not check to ensure that it is not a symbolic link. If an attacker creates a symbolic link on the filesystem with the path/filename of the logfile, transaction data will be written to the destination file as root.
Exploitation of this vulnerability may result in a denial of service if sensitive files are corrupted. As client-supplied data is written to the file, it may also be possible for this vulnerability to be exploited to elevate privileges.
CDE ships with a daemon called the ToolTalk database server. The ToolTalk database server allows for programs designed for use in CDE to communicate with each other. It is enabled by default on most systems shipped with CDE.
The ToolTalk database server is vulnerable to a symbolic link vulnerability that is exploitable by attackers with access to the filesystem.
The server logs transactions to logfiles with filenames based on the name of the ToolTalk database supplied by the client. When writing to the logfile, the server does not check to ensure that it is not a symbolic link. If an attacker creates a symbolic link on the filesystem with the path/filename of the logfile, transaction data will be written to the destination file as root.
Exploitation of this vulnerability may result in a denial of service if sensitive files are corrupted. As client-supplied data is written to the file, it may also be possible for this vulnerability to be exploited to elevate privileges.
Exploit / POC
Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
Solution:
HP has stated that HP-MPE/ix HP OpenVMS HP NonStop Servers are not vulnerable to this issue. HP has also revised an advisory with fix information. Users running HP-UX 10.10 are advised to contact [email protected] for fix information.
Compaq Computer Corporation
CROSS REFERENCE: SSRT2251
At this time Compaq does have solutions in final testing and will publish HP Tru64 UNIX security bulletin (SSRT2251) with patch information as soon as testing has completed and kits are available from the support ftp web site.
Cray, Inc.
Cray, Inc. does include ToolTalk within the CrayTools product. However, rpc.ttdbserverd is not turned on or used by any Cray provided application. Since a site may have turned this on for their own use, they can always remove the binary /opt/ctl/bin/rpc.ttdbserverd if they are concerned.
IBM Corporation
The CDE desktop product shipped with AIX is vulnerable to both the issues detailed above in the advisory. This affects AIX releases 4.3.3 and 5.1.0. Patches have been made available.
Sun Microsystems, Inc.
The Solaris RPC-based ToolTalk database server, rpc.ttdbserverd, is vulnerable to the two vulnerabilities [VU#975403 VU#299816] described in this advisory in all currently supported versions of Solaris:
Solaris 2.5.1, 2.6, 7, 8, and 9
Patches are available for the following releases:
2.6, 7, 8, and 9.
Xi Graphics
Xi Graphics deXtop CDE v2.1 is vulnerable to this attack. A update correcting this issue will be available on our ftp site once this vulnerability has been publically announced.
When announced, the update and accompanying text file will be:
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.txt
SGI has released a new advisory. A new patch, 4669, is available for IRIX 6.5.13 to 6.5.17.
Sun has released a revision of their advisory dealing with this issue. Please see the referenced advisory for more informaiton.
Sun Solaris 8_sparc
IBM AIX 5.1
Sun Solaris 2.6
Sun Solaris 2.6_x86
Sun Solaris 7.0
Sun Solaris 9
Sun Solaris 7.0_x86
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX 10.24
HP HP-UX 11.0
HP HP-UX 11.11
IBM AIX 4.3.3
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.10
SGI IRIX 6.5.10 m
SGI IRIX 6.5.10 f
SGI IRIX 6.5.11
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14
SGI IRIX 6.5.14 m
SGI IRIX 6.5.15
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.2
SGI IRIX 6.5.3 f
SGI IRIX 6.5.3
SGI IRIX 6.5.3 m
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4
SGI IRIX 6.5.4 f
SGI IRIX 6.5.5
SGI IRIX 6.5.5 f
SGI IRIX 6.5.5 m
SGI IRIX 6.5.6
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7
SGI IRIX 6.5.7 f
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8
SGI IRIX 6.5.8 f
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Solution:
HP has stated that HP-MPE/ix HP OpenVMS HP NonStop Servers are not vulnerable to this issue. HP has also revised an advisory with fix information. Users running HP-UX 10.10 are advised to contact [email protected] for fix information.
Compaq Computer Corporation
CROSS REFERENCE: SSRT2251
At this time Compaq does have solutions in final testing and will publish HP Tru64 UNIX security bulletin (SSRT2251) with patch information as soon as testing has completed and kits are available from the support ftp web site.
Cray, Inc.
Cray, Inc. does include ToolTalk within the CrayTools product. However, rpc.ttdbserverd is not turned on or used by any Cray provided application. Since a site may have turned this on for their own use, they can always remove the binary /opt/ctl/bin/rpc.ttdbserverd if they are concerned.
IBM Corporation
The CDE desktop product shipped with AIX is vulnerable to both the issues detailed above in the advisory. This affects AIX releases 4.3.3 and 5.1.0. Patches have been made available.
Sun Microsystems, Inc.
The Solaris RPC-based ToolTalk database server, rpc.ttdbserverd, is vulnerable to the two vulnerabilities [VU#975403 VU#299816] described in this advisory in all currently supported versions of Solaris:
Solaris 2.5.1, 2.6, 7, 8, and 9
Patches are available for the following releases:
2.6, 7, 8, and 9.
Xi Graphics
Xi Graphics deXtop CDE v2.1 is vulnerable to this attack. A update correcting this issue will be available on our ftp site once this vulnerability has been publically announced.
When announced, the update and accompanying text file will be:
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.tar.gz
ftp://ftp.xig.com/pub/updates/dextop/2.1/DEX2100.016.txt
SGI has released a new advisory. A new patch, 4669, is available for IRIX 6.5.13 to 6.5.17.
Sun has released a revision of their advisory dealing with this issue. Please see the referenced advisory for more informaiton.
Sun Solaris 8_sparc
-
Sun 110286-09
http://sunsolve.sun.com
IBM AIX 5.1
-
IBM IY32370
http://www.ibm.com/support
Sun Solaris 2.6
-
Sun 105802-18
http://sunsolve.sun.com
Sun Solaris 2.6_x86
-
Sun 105803-20
http://sunsolve.sun.com
Sun Solaris 7.0
-
Sun 107893-19
http://sunsolve.sun.com
Sun Solaris 9
-
Sun 112808-02
http://sunsolve.sun.com
Sun Solaris 7.0_x86
-
Sun 107894-19
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 110287-09
http://sunsolve.sun.com
HP HP-UX 10.10
-
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 10.20
-
HP PHSS_27426
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 10.24
-
HP PHSS_28173
http://itrc.hp.com
HP HP-UX 11.0
-
HP PHSS_27427
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
HP HP-UX 11.11
-
HP PHSS_27428
http://itrc.hp.com -
HP rpc.ttdbserver
FTP login credentials are required in order to access this fix. Username and password is ttdb1/ttdb1. Proper patches are forthcoming.
ftp://hprc.external.hp.com
IBM AIX 4.3.3
-
IBM IY32368
http://www.ibm.com/support
SGI IRIX 6.5
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.1
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.10 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.11 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.12
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.13
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.14 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.15 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.16 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17 m
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.17 f
-
SGI 4669
ftp://patches.sgi.com/ -
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.2
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.3 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.4 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.5 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.6 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.7 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.8 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9 f
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9 m
-
SGI 4799
http://patches.sgi.com
SGI IRIX 6.5.9
-
SGI 4799
http://patches.sgi.com
Caldera UnixWare 7.1.1
-
Caldera erg711831b.Z
ftp://ftp.caldera.com/pub/updates/UnixWare/CSSA-2001-SCO.28/erg711831b .Z
Caldera OpenUnix 8.0
-
Caldera erg712073.pkg.Z
ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.28/erg712073. pkg.Z
References
Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
References:
References:
- 46022 (Sun Microsystems)
- Sun Alert ID: 46022 - Multiple Vulnerabilities in the Tooltalk Database Server (Sun)