Multiple Vendor INN inews Buffer Overflow Vulnerability
BID:616
Info
Multiple Vendor INN inews Buffer Overflow Vulnerability
| Bugtraq ID: | 616 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 02 1999 12:00AM |
| Updated: | Sep 02 1999 12:00AM |
| Credit: | This vulnerability was orignally discovered on the Bugtraq mailing list, it was later addressed by both Redhat and and the ISC the maintainers of INN. Redhat posted their advisory via Cristian Gafton <[email protected]> to the Bugtraq mailing list on Wed, |
| Vulnerable: |
RedHat Linux 6.0 RedHat Linux 5.2 i386 RedHat Linux 5.1 RedHat Linux 5.0 RedHat Linux 4.2 RedHat Linux 4.1 ISC INN 2.2 ISC INN 2.1 ISC INN 2.0 ISC INN 1.7.2 ISC INN 1.7 ISC INN 1.5.1 |
| Not Vulnerable: | |
Discussion
Multiple Vendor INN inews Buffer Overflow Vulnerability
INN versions 2.2 and earlier have a buffer overflow-related security condition in the inews program.
inews is a program used to inject new postings into the news system. It is used by many news reading programs and scripts. The default installation is with inews setgid to the news group and world executable. It's possible that exploiting the buffer overflow could give the attacker news group privileges, which could possibly be extended to root access.
INN versions 2.2 and earlier have a buffer overflow-related security condition in the inews program.
inews is a program used to inject new postings into the news system. It is used by many news reading programs and scripts. The default installation is with inews setgid to the news group and world executable. It's possible that exploiting the buffer overflow could give the attacker news group privileges, which could possibly be extended to root access.
Exploit / POC
Multiple Vendor INN inews Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
Multiple Vendor INN inews Buffer Overflow Vulnerability
Solution:
The ISC, the maintainers of the INN package have made the following package available:
ftp://ftp.isc.org/isc/inn/inn-2.2.1.tar.gz
Below is the patch/source upgrades provided by RedHat. Work around information is available in the attached RedHat advisory.
Red Hat Linux 6.0:
==================
Intel:
ftp://updates.redhat.com//6.0/i386/inn-2.2.1-1.i386.rpm
ftp://updates.redhat.com//6.0/i386/inn-devel-2.2.1-1.i386.rpm
Alpha:
ftp://updates.redhat.com//6.0/alpha/inn-2.2.1-1.alpha.rpm
ftp://updates.redhat.com//6.0/alpha/inn-devel-2.2.1-1.alpha.rpm
Sparc:
ftp://updates.redhat.com//6.0/sparc/inn-2.2.1-1.sparc.rpm
ftp://updates.redhat.com//6.0/sparc/inn-devel-2.2.1-1.sparc.rpm
Source packages:
ftp://updates.redhat.com//6.0/SRPMS/inn-2.2.1-1.src.rpm
Red Hat Linux 5.2:
==================
ftp://updates.redhat.com//5.2/i386/inn-2.2.1-0.5.2.i386.rpm
ftp://updates.redhat.com//5.2/i386/inn-devel-2.2.1-0.5.2.i386.rpm
Alpha:
ftp://updates.redhat.com//5.2/alpha/inn-2.2.1-0.5.2.alpha.rpm
ftp://updates.redhat.com//5.2/alpha/inn-devel-2.2.1-0.5.2.alpha.rpm
Sparc:
ftp://updates.redhat.com//5.2/sparc/inn-2.2.1-0.5.2.sparc.rpm
ftp://updates.redhat.com//5.2/sparc/inn-devel-2.2.1-0.5.2.sparc.rpm
Source packages:
ftp://updates.redhat.com//5.2/SRPMS/inn-2.2.1-0.5.2.src.rpm
Red Hat Linux 4.2:
==================
Intel:
ftp://updates.redhat.com//4.2/i386/inn-2.2.1-0.4.2.i386.rpm
ftp://updates.redhat.com//4.2/i386/inn-devel-2.2.1-0.4.2.i386.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Alpha:
ftp://updates.redhat.com//4.2/alpha/inn-2.2.1-0.4.2.alpha.rpm
ftp://updates.redhat.com//4.2/alpha/inn-devel-2.2.1-0.4.2.alpha.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Sparc:
ftp://updates.redhat.com//4.2/sparc/inn-2.2.1-0.4.2.sparc.rpm
ftp://updates.redhat.com//4.2/sparc/inn-devel-2.2.1-0.4.2.sparc.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Source packages:
ftp://updates.redhat.com//4.2/SRPMS/cleanfeed-0.95.7b-0.4.2.src.rpm
ftp://updates.redhat.com//4.2/SRPMS/inn-2.2.1-0.4.2.src.rpm
Solution:
The ISC, the maintainers of the INN package have made the following package available:
ftp://ftp.isc.org/isc/inn/inn-2.2.1.tar.gz
Below is the patch/source upgrades provided by RedHat. Work around information is available in the attached RedHat advisory.
Red Hat Linux 6.0:
==================
Intel:
ftp://updates.redhat.com//6.0/i386/inn-2.2.1-1.i386.rpm
ftp://updates.redhat.com//6.0/i386/inn-devel-2.2.1-1.i386.rpm
Alpha:
ftp://updates.redhat.com//6.0/alpha/inn-2.2.1-1.alpha.rpm
ftp://updates.redhat.com//6.0/alpha/inn-devel-2.2.1-1.alpha.rpm
Sparc:
ftp://updates.redhat.com//6.0/sparc/inn-2.2.1-1.sparc.rpm
ftp://updates.redhat.com//6.0/sparc/inn-devel-2.2.1-1.sparc.rpm
Source packages:
ftp://updates.redhat.com//6.0/SRPMS/inn-2.2.1-1.src.rpm
Red Hat Linux 5.2:
==================
ftp://updates.redhat.com//5.2/i386/inn-2.2.1-0.5.2.i386.rpm
ftp://updates.redhat.com//5.2/i386/inn-devel-2.2.1-0.5.2.i386.rpm
Alpha:
ftp://updates.redhat.com//5.2/alpha/inn-2.2.1-0.5.2.alpha.rpm
ftp://updates.redhat.com//5.2/alpha/inn-devel-2.2.1-0.5.2.alpha.rpm
Sparc:
ftp://updates.redhat.com//5.2/sparc/inn-2.2.1-0.5.2.sparc.rpm
ftp://updates.redhat.com//5.2/sparc/inn-devel-2.2.1-0.5.2.sparc.rpm
Source packages:
ftp://updates.redhat.com//5.2/SRPMS/inn-2.2.1-0.5.2.src.rpm
Red Hat Linux 4.2:
==================
Intel:
ftp://updates.redhat.com//4.2/i386/inn-2.2.1-0.4.2.i386.rpm
ftp://updates.redhat.com//4.2/i386/inn-devel-2.2.1-0.4.2.i386.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Alpha:
ftp://updates.redhat.com//4.2/alpha/inn-2.2.1-0.4.2.alpha.rpm
ftp://updates.redhat.com//4.2/alpha/inn-devel-2.2.1-0.4.2.alpha.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Sparc:
ftp://updates.redhat.com//4.2/sparc/inn-2.2.1-0.4.2.sparc.rpm
ftp://updates.redhat.com//4.2/sparc/inn-devel-2.2.1-0.4.2.sparc.rpm
ftp://updates.redhat.com//4.2/noarch/cleanfeed-0.95.7b-0.4.2.noarch.rpm
Source packages:
ftp://updates.redhat.com//4.2/SRPMS/cleanfeed-0.95.7b-0.4.2.src.rpm
ftp://updates.redhat.com//4.2/SRPMS/inn-2.2.1-0.4.2.src.rpm
References
Multiple Vendor INN inews Buffer Overflow Vulnerability
References:
References:
- INN Homepage (ISC)
- Internet Software Consortium (ISC)
- Updates, Fixes, and Errata Page (RedHat)