AIX named-xfer File Overwrite Vulnerability
BID:673
Info
AIX named-xfer File Overwrite Vulnerability
| Bugtraq ID: | 673 |
| Class: | Unknown |
| CVE: |
CVE-1999-1013 |
| Remote: | No |
| Local: | No |
| Published: | Sep 23 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was discovered by Kyle Amon <[email protected]>. |
| Vulnerable: |
IBM AIX 4.2.1 IBM AIX 4.1.5 |
| Not Vulnerable: | |
Discussion
AIX named-xfer File Overwrite Vulnerability
A vulnerability in the 'named-xfer' executable allows members of the 'system' group to overwrite any file in the system.
The '/usr/sbin/named-xfer' file under AIX is setuid root and only executable by members of the 'system' group. By using the '-f' command line parameter to named-xfer members of the system group can overwrite any file on the system with a DNS zone file.
A cleverly written zone file used to overwrite say /.rhosts could be used to obtain root access to the system.
The defect ticket 287556 has been opened to fix this issue.
A vulnerability in the 'named-xfer' executable allows members of the 'system' group to overwrite any file in the system.
The '/usr/sbin/named-xfer' file under AIX is setuid root and only executable by members of the 'system' group. By using the '-f' command line parameter to named-xfer members of the system group can overwrite any file on the system with a DNS zone file.
A cleverly written zone file used to overwrite say /.rhosts could be used to obtain root access to the system.
The defect ticket 287556 has been opened to fix this issue.
Solution / Fix
AIX named-xfer File Overwrite Vulnerability
Solution:
Turn off the setuid bit from named-xfer. It is not required for its proper functioning.
Solution:
Turn off the setuid bit from named-xfer. It is not required for its proper functioning.
References
AIX named-xfer File Overwrite Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)