Multiple Vendor amd Buffer Overflow Vulnerability
BID:614
Info
Multiple Vendor amd Buffer Overflow Vulnerability
| Bugtraq ID: | 614 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 30 1999 12:00AM |
| Updated: | Aug 30 1999 12:00AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list as a RedHat advisory by Cristian Gafton <[email protected]> on Mon Aug 30 1999. |
| Vulnerable: |
Redhat Linux 6.0 Redhat Linux 5.2 i386 Redhat Linux 5.1 Redhat Linux 5.0 Redhat Linux 4.2 FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 BSDI BSD/OS 4.0.1 BSDI BSD/OS 3.1 |
| Not Vulnerable: | |
Discussion
Multiple Vendor amd Buffer Overflow Vulnerability
There is a remotely exploitable buffer overflow condition in the amd daemon under several operating systems. Amd is a daemon that automatically mounts filesystems whenever a file or directory within that filesystem is accessed. Filesystems are automatically unmounted when they appear to have become quiescent.
The vulnerability is in the log functions of the daemon.
Red Hat Linux 4.2 shipped originally with a version of amd that is no longer being maintained. Since Red Hat Linux 5.0 we have switched to am-utils. This release of am-utils has been backported to 4.2 and it will obsolete the original 4.2 amd package.
There is a remotely exploitable buffer overflow condition in the amd daemon under several operating systems. Amd is a daemon that automatically mounts filesystems whenever a file or directory within that filesystem is accessed. Filesystems are automatically unmounted when they appear to have become quiescent.
The vulnerability is in the log functions of the daemon.
Red Hat Linux 4.2 shipped originally with a version of amd that is no longer being maintained. Since Red Hat Linux 5.0 we have switched to am-utils. This release of am-utils has been backported to 4.2 and it will obsolete the original 4.2 amd package.
Exploit / POC
Multiple Vendor amd Buffer Overflow Vulnerability
exploit available
exploit available
Solution / Fix
Multiple Vendor amd Buffer Overflow Vulnerability
Solution:
BSD/OS:
-------
Apply mod M410-017 for 4.0.1 and mod M310-057 for 3;1. These are available from http://www.bsdi.com/support/patches.
FreeBSD:
--------
Upgrade your system to one of the following:
FreeBSD-3.3 RELEASE
FreeBSD-current as of September 7, 1999
FreeBSD-3.2-stable as of August 25, 1999
RedHat:
-------
RPMs required (for Red Hat Linux 6.0, 5.2 and 4.2 respectively):
Intel:
ftp://updates.redhat.com/6.0/i386/am-utils-6.0.1s11-1.6.0.i386.rpm
ftp://updates.redhat.com/5.2/i386/am-utils-6.0.1s11-1.5.2.i386.rpm
ftp://updates.redhat.com/4.2/i386/am-utils-6.0.1s11-1.4.2.i386.rpm
Alpha:
ftp://updates.redhat.com/6.0/alpha/am-utils-6.0.1s11-1.6.0.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/am-utils-6.0.1s11-1.5.2.alpha.rpm
ftp://updates.redhat.com/4.2/alpha/am-utils-6.0.1s11-1.4.2.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.0/sparc/am-utils-6.0.1s11-1.6.0.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/am-utils-6.0.1s11-1.5.2.sparc.rpm
ftp://updates.redhat.com/4.2/sparc/am-utils-6.0.1s11-1.4.2.sparc.rpm
Source packages:
ftp://updates.redhat.com/6.0/SRPMS/am-utils-6.0.1s11-1.6.0.src.rpm
ftp://updates.redhat.com/5.2/SRPMS/am-utils-6.0.1s11-1.5.2.src.rpm
ftp://updates.redhat.com/4.2/SRPMS/am-utils-6.0.1s11-1.4.2.src.rpm
MD5 sum Package Name
- --------------------------------------------------------------------------
0946dbc5539d208625eb27f506177ed2 i386/am-utils-6.0.1s11-1.6.0.i386.rpm
1a1ceb0ed50822776f605e60bbed1afb alpha/am-utils-6.0.1s11-1.6.0.alpha.rpm
b68c6f2780f11ca71947673124bd8f11 sparc/am-utils-6.0.1s11-1.6.0.sparc.rpm
275997ded7f0c85efa6229963e84f668 SRPMS/am-utils-6.0.1s11-1.6.0.src.rpm
e9a06fe4fdf56fdaa9fd984ef5988414 i386/am-utils-6.0.1s11-1.5.2.i386.rpm
617673437abaca052fe950c928722644 alpha/am-utils-6.0.1s11-1.5.2.alpha.rpm
23f3fbdf772eeb7ec67016d1c246225e sparc/am-utils-6.0.1s11-1.5.2.sparc.rpm
01ade16e4171a92fb1c10641846044a7 SRPMS/am-utils-6.0.1s11-1.5.2.src.rpm
cf75db7b60b1d27093685e345153dfcd i386/am-utils-6.0.1s11-1.4.2.i386.rpm
3ec0520caa1a587133ea6cc105f4fc34 alpha/am-utils-6.0.1s11-1.4.2.alpha.rpm
daf8bd0849c584e919fcd5ae8fb1e807 sparc/am-utils-6.0.1s11-1.4.2.sparc.rpm
0aa30be9b859eca2e003bb983c4839f5 SRPMS/am-utils-6.0.1s11-1.4.2.src.rpm
Solution:
BSD/OS:
-------
Apply mod M410-017 for 4.0.1 and mod M310-057 for 3;1. These are available from http://www.bsdi.com/support/patches.
FreeBSD:
--------
Upgrade your system to one of the following:
FreeBSD-3.3 RELEASE
FreeBSD-current as of September 7, 1999
FreeBSD-3.2-stable as of August 25, 1999
RedHat:
-------
RPMs required (for Red Hat Linux 6.0, 5.2 and 4.2 respectively):
Intel:
ftp://updates.redhat.com/6.0/i386/am-utils-6.0.1s11-1.6.0.i386.rpm
ftp://updates.redhat.com/5.2/i386/am-utils-6.0.1s11-1.5.2.i386.rpm
ftp://updates.redhat.com/4.2/i386/am-utils-6.0.1s11-1.4.2.i386.rpm
Alpha:
ftp://updates.redhat.com/6.0/alpha/am-utils-6.0.1s11-1.6.0.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/am-utils-6.0.1s11-1.5.2.alpha.rpm
ftp://updates.redhat.com/4.2/alpha/am-utils-6.0.1s11-1.4.2.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.0/sparc/am-utils-6.0.1s11-1.6.0.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/am-utils-6.0.1s11-1.5.2.sparc.rpm
ftp://updates.redhat.com/4.2/sparc/am-utils-6.0.1s11-1.4.2.sparc.rpm
Source packages:
ftp://updates.redhat.com/6.0/SRPMS/am-utils-6.0.1s11-1.6.0.src.rpm
ftp://updates.redhat.com/5.2/SRPMS/am-utils-6.0.1s11-1.5.2.src.rpm
ftp://updates.redhat.com/4.2/SRPMS/am-utils-6.0.1s11-1.4.2.src.rpm
MD5 sum Package Name
- --------------------------------------------------------------------------
0946dbc5539d208625eb27f506177ed2 i386/am-utils-6.0.1s11-1.6.0.i386.rpm
1a1ceb0ed50822776f605e60bbed1afb alpha/am-utils-6.0.1s11-1.6.0.alpha.rpm
b68c6f2780f11ca71947673124bd8f11 sparc/am-utils-6.0.1s11-1.6.0.sparc.rpm
275997ded7f0c85efa6229963e84f668 SRPMS/am-utils-6.0.1s11-1.6.0.src.rpm
e9a06fe4fdf56fdaa9fd984ef5988414 i386/am-utils-6.0.1s11-1.5.2.i386.rpm
617673437abaca052fe950c928722644 alpha/am-utils-6.0.1s11-1.5.2.alpha.rpm
23f3fbdf772eeb7ec67016d1c246225e sparc/am-utils-6.0.1s11-1.5.2.sparc.rpm
01ade16e4171a92fb1c10641846044a7 SRPMS/am-utils-6.0.1s11-1.5.2.src.rpm
cf75db7b60b1d27093685e345153dfcd i386/am-utils-6.0.1s11-1.4.2.i386.rpm
3ec0520caa1a587133ea6cc105f4fc34 alpha/am-utils-6.0.1s11-1.4.2.alpha.rpm
daf8bd0849c584e919fcd5ae8fb1e807 sparc/am-utils-6.0.1s11-1.4.2.sparc.rpm
0aa30be9b859eca2e003bb983c4839f5 SRPMS/am-utils-6.0.1s11-1.4.2.src.rpm
References
Multiple Vendor amd Buffer Overflow Vulnerability
References:
References:
- Updates, Fixes, and Errata Page (RedHat)