Util-linux File Locking Race Condition Vulnerability
BID:5344
Info
Util-linux File Locking Race Condition Vulnerability
| Bugtraq ID: | 5344 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 29 2002 12:00AM |
| Credit: | Discovered by Michal Zalewski <[email protected]>. |
| Vulnerable: |
Redhat util-linux-2.11n-12.i386.rpm Redhat util-linux-2.10s-12.i386.rpm Redhat util-linux-2.10m-12.i386.rpm Redhat util-linux-2.10f-7.i386.rpm Redhat mount-2.11n-12.i386.rpm Redhat losetup-2.11n-12.i386.rpm Redhat Linux 7.3 Redhat Linux 7.2 ia64 Redhat Linux 7.2 alpha Redhat Linux 7.2 Redhat Linux 7.1 ia64 Redhat Linux 7.1 alpha Redhat Linux 7.1 Redhat Linux 7.0 alpha Redhat Linux 7.0 Redhat Linux 6.2 sparc Redhat Linux 6.2 alpha Redhat Linux 6.1 sparc Redhat Linux 6.1 alpha Redhat Linux 6.1 Redhat Linux 6.0 sparc Redhat Linux 6.0 alpha Redhat Linux 6.0 Redhat Linux 6.2 Mandriva Linux Mandrake 8.2 ppc Mandriva Linux Mandrake 8.2 Mandriva Linux Mandrake 8.1 ia64 Mandriva Linux Mandrake 8.1 Mandriva Linux Mandrake 8.0 ppc Mandriva Linux Mandrake 8.0 Mandriva Linux Mandrake 7.2 Mandriva Linux Mandrake 7.1 Mandriva Linux Mandrake 7.0 MandrakeSoft Single Network Firewall 7.2 MandrakeSoft Corporate Server 1.0.1 HP Secure OS software for Linux 1.0 Caldera OpenLinux Workstation 3.1.1 Caldera OpenLinux Workstation 3.1 Caldera OpenLinux Server 3.1.1 Caldera OpenLinux Server 3.1 |
| Not Vulnerable: | |
Discussion
Util-linux File Locking Race Condition Vulnerability
The util-linux package is a set of commonly used system utilities such as 'chfn' and 'chsh'. It is included with many Linux distributions.
A race condition has been reported in code shared by the util-linux utilities. The condition is related to file locking. Failure to check for the existence of a lockfile prior to sensitive operations may, under specific circumstances, open a window of opportunity for attack. The util-linux utilities often write to sensitive files such as /etc/passwd/. Attackers may exploit the condition to inject arbitrary data into these files to elevate privileges.
The reported attacks are complex, time dependent and require specific circumstances such as system administrator interaction and a large passwd file.
Red Hat Linux is known to ship with util-linux as a core component. Other distributions, those that are derived from Red Hat in particular, may also be vulnerable.
It should be noted that the utilities included with the shadow-utils package (shipped with SuSE Linux) are not vulnerable.
The util-linux package is a set of commonly used system utilities such as 'chfn' and 'chsh'. It is included with many Linux distributions.
A race condition has been reported in code shared by the util-linux utilities. The condition is related to file locking. Failure to check for the existence of a lockfile prior to sensitive operations may, under specific circumstances, open a window of opportunity for attack. The util-linux utilities often write to sensitive files such as /etc/passwd/. Attackers may exploit the condition to inject arbitrary data into these files to elevate privileges.
The reported attacks are complex, time dependent and require specific circumstances such as system administrator interaction and a large passwd file.
Red Hat Linux is known to ship with util-linux as a core component. Other distributions, those that are derived from Red Hat in particular, may also be vulnerable.
It should be noted that the utilities included with the shadow-utils package (shipped with SuSE Linux) are not vulnerable.
Exploit / POC
Util-linux File Locking Race Condition Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Util-linux File Locking Race Condition Vulnerability
Solution:
An unofficial source code patch is available. Red Hat has released fixes in bulletin RHSA-2002:132-14 (see references section).
Users of HP Secure OS Software for Linux Release 1.0 are advised to install the available Red Hat fixes.
SCO has released a security advisory. Fixes are available.
Fixes:
Redhat util-linux-2.10s-12.i386.rpm
Redhat Linux 6.2
Redhat util-linux-2.11n-12.i386.rpm
Redhat util-linux-2.10m-12.i386.rpm
Redhat mount-2.11n-12.i386.rpm
Redhat util-linux-2.10f-7.i386.rpm
Redhat losetup-2.11n-12.i386.rpm
MandrakeSoft Corporate Server 1.0.1
Caldera OpenLinux Server 3.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
Redhat Linux 6.2 alpha
Redhat Linux 6.2 sparc
Redhat Linux 7.0
Redhat Linux 7.0 alpha
Mandriva Linux Mandrake 7.1
Redhat Linux 7.1 alpha
Redhat Linux 7.1 ia64
Redhat Linux 7.1
Mandriva Linux Mandrake 7.2
Redhat Linux 7.2 ia64
Redhat Linux 7.2
MandrakeSoft Single Network Firewall 7.2
Redhat Linux 7.2 alpha
Redhat Linux 7.3
Mandriva Linux Mandrake 8.0 ppc
Mandriva Linux Mandrake 8.0
Mandriva Linux Mandrake 8.1 ia64
Mandriva Linux Mandrake 8.1
Mandriva Linux Mandrake 8.2
Mandriva Linux Mandrake 8.2 ppc
Solution:
An unofficial source code patch is available. Red Hat has released fixes in bulletin RHSA-2002:132-14 (see references section).
Users of HP Secure OS Software for Linux Release 1.0 are advised to install the available Red Hat fixes.
SCO has released a security advisory. Fixes are available.
Fixes:
Redhat util-linux-2.10s-12.i386.rpm
-
Red Hat util-linux-2.11f-17.7.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/util-linux-2.11f-17.7.2.i386.r pm
Redhat Linux 6.2
-
Red Hat util-linux-2.10f-7.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/util-linux-2.10f-7.6.2.i386.rp m -
Red Hat util-linux-2.10f-7.6.2.src.rpm
ftp://updates.redhat.com/6.2/en/os/SRPMS/util-linux-2.10f-7.6.2.src.rp m
Redhat util-linux-2.11n-12.i386.rpm
-
Red Hat util-linux-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/util-linux-2.11n-12.7.3.i386.r pm
Redhat util-linux-2.10m-12.i386.rpm
-
Red Hat util-linux-2.10m-12.7.0.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/util-linux-2.10m-12.7.0.i386.r pm
Redhat mount-2.11n-12.i386.rpm
-
Red Hat mount-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mount-2.11n-12.7.3.i386.rpm
Redhat util-linux-2.10f-7.i386.rpm
-
Red Hat util-linux-2.10f-7.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/util-linux-2.10f-7.6.2.i386.rp m
Redhat losetup-2.11n-12.i386.rpm
-
Red Hat losetup-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/losetup-2.11n-12.7.3.i386.rpm
MandrakeSoft Corporate Server 1.0.1
-
Mandrake util-linux-2.10o-6.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Caldera OpenLinux Server 3.1
-
SCO util-linux-2.11l-5.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-043.0/RPM S -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-043.0/SRP MS -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-043. 0/SRPMS
Caldera OpenLinux Workstation 3.1
-
SCO util-linux-2.11l-5.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-043. 0/RPMS -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-043. 0/SRPMS
Caldera OpenLinux Server 3.1.1
-
SCO util-linux-2.11l-5.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-043.0/R PMS -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-043.0/S RPMS -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-043. 0/SRPMS
Caldera OpenLinux Workstation 3.1.1
-
SCO util-linux-2.11l-5.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-04 3.0/RPMS -
SCO util-linux-2.11l-5.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-04 3.0/SRPMS
Redhat Linux 6.2 alpha
-
Red Hat util-linux-2.10f-7.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/util-linux-2.10f-7.6.2.alpha. rpm -
Red Hat util-linux-2.10f-7.6.2.src.rpm
ftp://updates.redhat.com/6.2/en/os/SRPMS/util-linux-2.10f-7.6.2.src.rp m
Redhat Linux 6.2 sparc
-
Red Hat util-linux-2.10f-7.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/util-linux-2.10f-7.6.2.sparc. rpm -
Red Hat util-linux-2.10f-7.6.2.src.rpm
ftp://updates.redhat.com/6.2/en/os/SRPMS/util-linux-2.10f-7.6.2.src.rp m
Redhat Linux 7.0
-
Red Hat util-linux-2.10m-12.7.0.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/util-linux-2.10m-12.7.0.i386.r pm -
Red Hat util-linux-2.10m-12.7.0.src.rpm
ftp://updates.redhat.com/7.0/en/os/SRPMS/util-linux-2.10m-12.7.0.src.r pm
Redhat Linux 7.0 alpha
-
Red Hat util-linux-2.10m-12.7.0.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/util-linux-2.10m-12.7.0.alpha .rpm -
Red Hat util-linux-2.10m-12.7.0.src.rpm
ftp://updates.redhat.com/7.0/en/os/SRPMS/util-linux-2.10m-12.7.0.src.r pm
Mandriva Linux Mandrake 7.1
-
Mandrake util-linux-2.10o-6.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Redhat Linux 7.1 alpha
-
Red Hat util-linux-2.11f-17.7.2.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/util-linux-2.11f-17.7.2.alpha .rpm -
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.1/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
Redhat Linux 7.1 ia64
-
Red Hat util-linux-2.11f-17.7.2.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/util-linux-2.11f-17.7.2.ia64.r pm -
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.1/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
Redhat Linux 7.1
-
Red Hat util-linux-2.11f-17.7.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/util-linux-2.11f-17.7.2.i386.r pm -
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.1/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
Mandriva Linux Mandrake 7.2
-
Mandrake util-linux-2.10o-6.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Redhat Linux 7.2 ia64
-
Red Hat util-linux-2.11f-17.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/util-linux-2.11f-17.7.2.ia64.r pm -
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.2/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
Redhat Linux 7.2
-
Red Hat util-linux-2.11f-17.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/util-linux-2.11f-17.7.2.i386.r pm -
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.2/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
MandrakeSoft Single Network Firewall 7.2
-
Mandrake util-linux-2.10o-6.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Redhat Linux 7.2 alpha
-
Red Hat util-linux-2.11f-17.7.2.src.rpm
ftp://updates.redhat.com/7.2/en/os/SRPMS/util-linux-2.11f-17.7.2.src.r pm
Redhat Linux 7.3
-
Michal Zalewski setpwnam.patch
Unofficial source code patch. Applies to util-linux-2.11nn.
http://www.securityfocus.com/data/vulnerabilities/patches/setpwnam.pat ch -
Red Hat losetup-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/losetup-2.11n-12.7.3.i386.rpm -
Red Hat mount-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mount-2.11n-12.7.3.i386.rpm -
Red Hat util-linux-2.11n-12.7.3.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/util-linux-2.11n-12.7.3.i386.r pm -
Red Hat util-linux-2.11n-12.7.3.src.rpm
ftp://updates.redhat.com/7.3/en/os/SRPMS/util-linux-2.11n-12.7.3.src.r pm
Mandriva Linux Mandrake 8.0 ppc
-
Mandrake util-linux-2.11h-3.5mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 8.0
-
Mandrake util-linux-2.10s-3.2mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 8.1 ia64
-
Mandrake util-linux-2.11h-3.5mdk.ia64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 8.1
-
Mandrake util-linux-2.11h-3.5mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 8.2
-
Mandrake losetup-2.11n-4.3mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mount-2.11n-4.3mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake util-linux-2.11n-4.3mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 8.2 ppc
-
Mandrake losetup-2.11n-4.3mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mount-2.11n-4.3mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake util-linux-2.11n-4.3mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php
References
Util-linux File Locking Race Condition Vulnerability
References:
References: