Stunnel Leaked File Descriptor Vulnerability
BID:8537
Info
Stunnel Leaked File Descriptor Vulnerability
| Bugtraq ID: | 8537 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0740 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 03 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery of this issue has been credited to Steve Grubb <[email protected]>. |
| Vulnerable: |
Stunnel Stunnel 4.0 0 Stunnel Stunnel 3.24 Stunnel Stunnel 3.22 Stunnel Stunnel 3.21 c Stunnel Stunnel 3.21 b Stunnel Stunnel 3.21 a Stunnel Stunnel 3.21 Stunnel Stunnel 3.19 Stunnel Stunnel 3.18 Stunnel Stunnel 3.17 Stunnel Stunnel 3.16 Stunnel Stunnel 3.15 Stunnel Stunnel 3.14 Stunnel Stunnel 3.13 Stunnel Stunnel 3.12 Stunnel Stunnel 3.11 Stunnel Stunnel 3.9 Stunnel Stunnel 3.8 Stunnel Stunnel 3.7 Stunnel Stunnel 3.4 a Stunnel Stunnel 3.3 Stunnel Stunnel 3.20 Stunnel Stunnel 3.10 SGI ProPack 2.3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 9.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 |
| Not Vulnerable: |
Stunnel Stunnel 4.0 4 Stunnel Stunnel 4.0 3 Stunnel Stunnel 4.0 2 Stunnel Stunnel 4.0 1 Stunnel Stunnel 3.26 |
Exploit / POC
Stunnel Leaked File Descriptor Vulnerability
The following proof of code has been supplied:
To compile:
$(CC) $(CFLAGS) -o $@ leak-sploit.c -lssl
To run the POC code, you can execute it directly as the
local program (-l argument) for Stunnel :
/usr/sbin/stunnel -s nobody -g nobody -D 7 -p
/etc/ssl/certs/stunnel.pem -o /tmp/stunnel.log -P
/tmp/stunnel.pid -d 2222 -l
/opt/stunnel-sploit/leak-sploit -- leak-sploit
Then connect to stunnel like: lynx https://localhost:2222
The following proof of code has been supplied:
To compile:
$(CC) $(CFLAGS) -o $@ leak-sploit.c -lssl
To run the POC code, you can execute it directly as the
local program (-l argument) for Stunnel :
/usr/sbin/stunnel -s nobody -g nobody -D 7 -p
/etc/ssl/certs/stunnel.pem -o /tmp/stunnel.log -P
/tmp/stunnel.pid -d 2222 -l
/opt/stunnel-sploit/leak-sploit -- leak-sploit
Then connect to stunnel like: lynx https://localhost:2222
Solution / Fix
Stunnel Leaked File Descriptor Vulnerability
Solution:
Conectiva has released an advisory (CLA-2003:736) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released advisories RHSA-2003:297-07 and RHSA-2003:296-01 to address this issue. See the referenced advisories for additional details.
Mandrake has released a security advisory (MDKSA-2003:108) to address this issue in 9.0 and Corporate Server 2.1. Users are advised to upgrade as soon as possible.
SGI has released an advisory (20031103-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10033) containing updated RPM packages relating to a number of different BIDS.
Patch 10033 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10033, please see the attached advisory.
The vendor has released upgrades to address this issue:
Stunnel Stunnel 3.20
Stunnel Stunnel 3.10
MandrakeSoft Corporate Server 2.1
MandrakeSoft Corporate Server 2.1 x86_64
Stunnel Stunnel 3.11
Stunnel Stunnel 3.12
Stunnel Stunnel 3.13
Stunnel Stunnel 3.14
Stunnel Stunnel 3.15
Stunnel Stunnel 3.16
Stunnel Stunnel 3.17
Stunnel Stunnel 3.18
Stunnel Stunnel 3.19
Stunnel Stunnel 3.21
Stunnel Stunnel 3.21 c
Stunnel Stunnel 3.21 b
Stunnel Stunnel 3.21 a
Stunnel Stunnel 3.22
Stunnel Stunnel 3.24
Stunnel Stunnel 3.3
Stunnel Stunnel 3.4 a
Stunnel Stunnel 3.7
Stunnel Stunnel 3.8
Stunnel Stunnel 3.9
Stunnel Stunnel 4.0 0
Mandriva Linux Mandrake 9.0
Solution:
Conectiva has released an advisory (CLA-2003:736) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released advisories RHSA-2003:297-07 and RHSA-2003:296-01 to address this issue. See the referenced advisories for additional details.
Mandrake has released a security advisory (MDKSA-2003:108) to address this issue in 9.0 and Corporate Server 2.1. Users are advised to upgrade as soon as possible.
SGI has released an advisory (20031103-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10033) containing updated RPM packages relating to a number of different BIDS.
Patch 10033 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10033, please see the attached advisory.
The vendor has released upgrades to address this issue:
Stunnel Stunnel 3.20
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.10
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
MandrakeSoft Corporate Server 2.1
-
MandrakeSoft stunnel-3.26-1.1.C21mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
MandrakeSoft Corporate Server 2.1 x86_64
-
MandrakeSoft stunnel-3.26-1.1.C21mdk.x86_64.rpm
http://www.mandrakesecure.net/en/ftp.php
Stunnel Stunnel 3.11
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.12
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.13
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.14
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.15
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.16
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.17
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.18
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz -
Stunnel stunnel-4.04.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-4.04.tar.gz
Stunnel Stunnel 3.19
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz -
Stunnel stunnel-4.04.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-4.04.tar.gz
Stunnel Stunnel 3.21
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz -
Stunnel stunnel-4.04.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-4.04.tar.gz
Stunnel Stunnel 3.21 c
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.21 b
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.21 a
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.22
-
Conectiva stunnel-3.26-1U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/stunnel-3.26-1U80_1cl.i386. rpm -
Conectiva stunnel-3.26-21517U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/stunnel-3.26-21517U90_1cl.i 386.rpm -
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.24
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.3
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.4 a
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.7
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.8
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 3.9
-
Stunnel stunnel-3.26.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-3.26.tar.gz
Stunnel Stunnel 4.0 0
-
Stunnel stunnel-4.04.tar.gz
http://www.stunnel.org/download/stunnel/src/stunnel-4.04.tar.gz
Mandriva Linux Mandrake 9.0
-
MandrakeSoft stunnel-3.26-1.1.90mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
References
Stunnel Leaked File Descriptor Vulnerability
References:
References:
- RHSA-2003:297-07 Updated stunnel packages available (RedHat)
- Stunnel Home Page (Stunnel)
- Stunnel-3.x Daemon Hijacking (Steve Grubb
)