Coreutils LS Width Argument Integer Overflow Vulnerability
BID:8875
Info
Coreutils LS Width Argument Integer Overflow Vulnerability
| Bugtraq ID: | 8875 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0853 CVE-2003-0854 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Vulnerability discovery credited to a source that has requested not to be credited in this database. |
| Vulnerable: |
Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.1 Washington University wu-ftpd 2.6 .0 Washington University wu-ftpd 2.5 .0 Washington University wu-ftpd 2.4.2 academ[BETA1-15] Washington University wu-ftpd 2.4.2 academ[BETA-18] Washington University wu-ftpd 2.4.2 VR17 Washington University wu-ftpd 2.4.2 VR16 Washington University wu-ftpd 2.4.2 (beta 18) VR9 Washington University wu-ftpd 2.4.2 (beta 18) VR8 Washington University wu-ftpd 2.4.2 (beta 18) VR7 Washington University wu-ftpd 2.4.2 (beta 18) VR6 Washington University wu-ftpd 2.4.2 (beta 18) VR5 Washington University wu-ftpd 2.4.2 (beta 18) VR4 Washington University wu-ftpd 2.4.2 (beta 18) VR15 Washington University wu-ftpd 2.4.2 (beta 18) VR14 Washington University wu-ftpd 2.4.2 (beta 18) VR13 Washington University wu-ftpd 2.4.2 (beta 18) VR12 Washington University wu-ftpd 2.4.2 (beta 18) VR11 Washington University wu-ftpd 2.4.2 (beta 18) VR10 Washington University wu-ftpd 2.4.1 Sun Cobalt RaQ XTR Sun Cobalt RaQ 4 Sun Cobalt Qube 3 SGI ProPack 2.3 SGI ProPack 2.2.1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 GNU fileutils 4.1.11 GNU fileutils 4.1.9 GNU fileutils 4.1.7 GNU fileutils 4.1.6 GNU fileutils 4.1.5 GNU fileutils 4.1.1 GNU fileutils 4.1 GNU fileutils 4.0.36 GNU fileutils 4.0.33 GNU fileutils 4.0 GNU Coreutils 5.0 GNU Coreutils 4.5.12 GNU Coreutils 4.5.11 GNU Coreutils 4.5.10 GNU Coreutils 4.5.9 GNU Coreutils 4.5.8 GNU Coreutils 4.5.7 GNU Coreutils 4.5.6 GNU Coreutils 4.5.5 GNU Coreutils 4.5.4 GNU Coreutils 4.5.3 GNU Coreutils 4.5.2 GNU Coreutils 4.5.1 Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: | |
Discussion
Coreutils LS Width Argument Integer Overflow Vulnerability
Coreutils 'ls' has been reported prone to an integer overflow vulnerability. The issue reportedly presents itself when handling width and column display command line arguments. It has been reported that excessive values passed as a width argument to 'ls' may cause an internal integer value to be misrepresented. Further arithmetic performed based off this misrepresented value may have unintentional results.
Additionally it has been reported that this vulnerability may be exploited in software that implements and invokes the vulnerable 'ls' utility to trigger a denial of service in the affected software.
Coreutils 'ls' has been reported prone to an integer overflow vulnerability. The issue reportedly presents itself when handling width and column display command line arguments. It has been reported that excessive values passed as a width argument to 'ls' may cause an internal integer value to be misrepresented. Further arithmetic performed based off this misrepresented value may have unintentional results.
Additionally it has been reported that this vulnerability may be exploited in software that implements and invokes the vulnerable 'ls' utility to trigger a denial of service in the affected software.
Exploit / POC
Coreutils LS Width Argument Integer Overflow Vulnerability
No exploit is explicitly required to carry out an attack. However, a program has been released which is designed to automate the necessary operations.
A new exploit has been made available (wu-freeze.c) by Angelo Rosiello.
No exploit is explicitly required to carry out an attack. However, a program has been released which is designed to automate the necessary operations.
A new exploit has been made available (wu-freeze.c) by Angelo Rosiello.
Solution / Fix
Coreutils LS Width Argument Integer Overflow Vulnerability
Solution:
This issue is reported to have been fixed in coreutils fileutils CVS tree.
Sun has released fixes to address this issue in Sun Cobalt Qube 3 and Cobalt RaQ XTR products. The fixes are linked below.
Sun has released a fix to address this issue in Sun Cobalt RaQ4. The fix is linked below.
Turbolinux have released an advisory (TLSA-2003-60) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory.
Red Hat has released an advisory (RHSA-2003:310-10) that addresses this issue on Red Hat Enterprise edition Linux. Customers who are potentially affected by this vulnerability are advised to apply appropriate fixes as soon as possible. Customers can download these fixes from the Red Hat network; further information is available in the referenced advisory.
Conectiva has released an advisory (CLA-2003:768) and fixes to address this issue. Affected users are advised to apply these fixes as soon as possible.
Conectiva has released a follow up to advisory (CLA-2003:768). The new advisory (CLA-2003:771) concerns the anonftp package that contains a copy of
the vulnerable ls program. Affected users are advised to apply these fixes as soon as possible.
Immunix has released an advisory (IMNX-2003-7+-026-01) and fixes to address this issue. Affected users are advised to apply these fixes as soon as possible.
Red Hat has released a security advisory (RHSA-2003:309-01) containing fixes.
Mandrake has released an advisory (MDKSA-2003:106) that includes updates to address the issue. Please see the attached advisory for details on obtaining and applying fixes.
An advisory has been released for Trustix Secure Linux (TSLSA-2003-0042) that includes updates for this issue. Please see the attached advisory for details on obtaining and applying updates.
SGI has released an advisory (20031101-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10032) containing updated RPM packages relating to a number of different BIDS.
Patch 10032 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10032, please see the attached advisory.
Sun has released fixes for Sun Linux.
SCO has released fixes for OpenLinux 3.1.1 Server and Workstation.
Debian has released advisory DSA 705-1 along with fixes dealing with this issue for their wu-ftp packages. Please see the referenced advisory for more information.
Avaya has released advisory ASA-2005-213 to indicate that Avaya CVLAN and Integrated Management products are vulnerable to this issue. Customers are advised to apply patches supplied by vendors of the underlying operating systems. Please see the referenced advisory for more information.
Sun Cobalt RaQ 4
Sun Cobalt RaQ XTR
Sun Cobalt Qube 3
Washington University wu-ftpd 2.6.1
Washington University wu-ftpd 2.6.2
GNU fileutils 4.0.33
GNU fileutils 4.0.36
GNU fileutils 4.1
GNU fileutils 4.1.1
GNU fileutils 4.1.11
GNU fileutils 4.1.5
GNU fileutils 4.1.9
GNU Coreutils 4.5.3
GNU Coreutils 4.5.7
GNU Coreutils 5.0
Solution:
This issue is reported to have been fixed in coreutils fileutils CVS tree.
Sun has released fixes to address this issue in Sun Cobalt Qube 3 and Cobalt RaQ XTR products. The fixes are linked below.
Sun has released a fix to address this issue in Sun Cobalt RaQ4. The fix is linked below.
Turbolinux have released an advisory (TLSA-2003-60) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory.
Red Hat has released an advisory (RHSA-2003:310-10) that addresses this issue on Red Hat Enterprise edition Linux. Customers who are potentially affected by this vulnerability are advised to apply appropriate fixes as soon as possible. Customers can download these fixes from the Red Hat network; further information is available in the referenced advisory.
Conectiva has released an advisory (CLA-2003:768) and fixes to address this issue. Affected users are advised to apply these fixes as soon as possible.
Conectiva has released a follow up to advisory (CLA-2003:768). The new advisory (CLA-2003:771) concerns the anonftp package that contains a copy of
the vulnerable ls program. Affected users are advised to apply these fixes as soon as possible.
Immunix has released an advisory (IMNX-2003-7+-026-01) and fixes to address this issue. Affected users are advised to apply these fixes as soon as possible.
Red Hat has released a security advisory (RHSA-2003:309-01) containing fixes.
Mandrake has released an advisory (MDKSA-2003:106) that includes updates to address the issue. Please see the attached advisory for details on obtaining and applying fixes.
An advisory has been released for Trustix Secure Linux (TSLSA-2003-0042) that includes updates for this issue. Please see the attached advisory for details on obtaining and applying updates.
SGI has released an advisory (20031101-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10032) containing updated RPM packages relating to a number of different BIDS.
Patch 10032 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10032, please see the attached advisory.
Sun has released fixes for Sun Linux.
SCO has released fixes for OpenLinux 3.1.1 Server and Workstation.
Debian has released advisory DSA 705-1 along with fixes dealing with this issue for their wu-ftp packages. Please see the referenced advisory for more information.
Avaya has released advisory ASA-2005-213 to indicate that Avaya CVLAN and Integrated Management products are vulnerable to this issue. Customers are advised to apply patches supplied by vendors of the underlying operating systems. Please see the referenced advisory for more information.
Sun Cobalt RaQ 4
-
Sun RaQ4-All-Security-2.0.1-16648.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-All-Security-2.0. 1-16648.pkg
Sun Cobalt RaQ XTR
-
Sun RaQXTR-All-Security-1.0.1-16648.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16648.pkg
Sun Cobalt Qube 3
-
Sun Qube3-All-Security-4.0.1-16648.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0 .1-16648.pkg
Washington University wu-ftpd 2.6.1
-
Conectiva anonftp-3.0-7U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/anonftp-3.0-7U70_1cl.i386 .rpm
Washington University wu-ftpd 2.6.2
-
Debian wu-ftpd_2.6.2-3woody5_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_alpha.deb -
Debian wu-ftpd_2.6.2-3woody5_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_arm.deb -
Debian wu-ftpd_2.6.2-3woody5_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_hppa.deb -
Debian wu-ftpd_2.6.2-3woody5_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_i386.deb -
Debian wu-ftpd_2.6.2-3woody5_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_ia64.deb -
Debian wu-ftpd_2.6.2-3woody5_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_m68k.deb -
Debian wu-ftpd_2.6.2-3woody5_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_mips.deb -
Debian wu-ftpd_2.6.2-3woody5_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_mipsel.deb -
Debian wu-ftpd_2.6.2-3woody5_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_powerpc.deb -
Debian wu-ftpd_2.6.2-3woody5_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_s390.deb -
Debian wu-ftpd_2.6.2-3woody5_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wu-ftpd/wu-ftpd_2.6.2-3 woody5_sparc.deb
GNU fileutils 4.0.33
-
TurboLinux fileutils-4.0.33-15.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/AdvancedServ er/6/ja/updates/RPMS/fileutils-4.0.33-15.i386.rpm -
TurboLinux fileutils-4.0.33-15.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.1/j a/updates/RPMS/fileutils-4.0.33-15.i386.rpm -
TurboLinux fileutils-4.0.33-15.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/6.5/u pdates/RPMS/fileutils-4.0.33-15.i386.rpm -
TurboLinux fileutils-4.0.33-15.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 6.0/ja/updates/RPMS/fileutils-4.0.33-15.i386.rpm -
TurboLinux fileutils-4.0.33-15.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/fileutils-4.0.33-15.i586.rpm -
TurboLinux fileutils-4.0.33-15.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/fileutils-4.0.33-15.i586.rpm -
TurboLinux fileutils-4.0.33-15.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/fileutils-4.0.33-15.i586.rpm -
TurboLinux fileutils-4.0.33-15.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/fileutils-4.0.33-15.i586.rpm
GNU fileutils 4.0.36
-
Red Hat fileutils-4.0.36-4.1.ppc.rpm
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/fileutils-4.0.36-4.1.pp c.rpm -
Red Hat fileutils-4.0.36-4.1.ppc.rpm
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/fileutils-4.0.36-4.1.pp c.rpm -
Red Hat fileutils-4.0.36-4.3.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/fileutils-4.0.36-4.3.i386.rpm
GNU fileutils 4.1
-
Red Hat fileutils-4.1-10.4.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/fileutils-4.1-10.4.i386.rpm -
Red Hat fileutils-4.1-10.4.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/fileutils-4.1-10.4.i386.rpm -
Red Hat fileutils-4.1-10.4.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/fileutils-4.1-10.4.ia64.rpm -
SCO fileutils-4.1-6.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-006.0/R PMS/fileutils-4.1-6.i386.rpm -
SCO fileutils-4.1-6.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-00 6.0/RPMS/fileutils-4.1-6.i386.rpm -
Sun fileutils-4.1-10.4.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/fileutils-4.1-10.4.i386.rpm -
Trustix fileutils-4.1-3tr.i586.rpm
Secure Linux 1.5 & 1.2
ftp://ftp.trustix.org/pub/trustix/updates/
GNU fileutils 4.1.1
-
Mandrake fileutils-4.1.11-6.1.90mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
TurboLinux fileutils-4.1.10-6.i586.rpm
Turbolinux 10 Desktop
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/fileutils-4.1.10-6.i586.rpm
GNU fileutils 4.1.11
-
Mandrake fileutils-4.1.11-6.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake fileutils-4.1.11-6.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
GNU fileutils 4.1.5
-
Mandrake fileutils-4.1.5-4.2.M82mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php
GNU fileutils 4.1.9
-
Red Hat fileutils-4.1.9-11.2.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/fileutils-4.1.9-11.2.i386.rpm
GNU Coreutils 4.5.3
-
Red Hat coreutils-4.5.3-19.0.2.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/coreutils-4.5.3-19.0.2.i386.rpm
GNU Coreutils 4.5.7
-
Mandrake coreutils-4.5.7-1.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-4.5.7-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-doc-4.5.7-1.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-doc-4.5.7-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
GNU Coreutils 5.0
-
Mandrake coreutils-5.0-6.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-5.0-7.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-doc-5.0-6.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake coreutils-doc-5.0-7.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Trustix anonftp-2.8-3tr.i586.rpm
Secure Linux 1.5 & 1.2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix coreutils-5.0-9tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix coreutils-doc-5.0-9tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/
References
Coreutils LS Width Argument Integer Overflow Vulnerability
References:
References:
- ASA-2005-213 - Updated fileutils/coreutils package fix ls vulnerabilties (Avaya)
- GNU Homepage (GNU)
- integer overflow in /bin/ls (GNU)
- RHSA-2003:310-10 Updated fileutils packages fix ls vulnerabilities (Red Hat)
- Sun Cobalt Qube 3 Patches (Sun)
- Sun Cobalt RaQ 4 Patches (Sun)
- Sun Cobalt RaQ XTR Patches (Sun)
- Re: WU-FTPD 2.6.2 Freezer (Seth Arnold
) - WU-FTPD 2.6.2 Freezer (Angelo Rosiello
)