Security Advisory Setuid bits are removed on dump to prevent exploit

Advisory: RHSA-2000:100-02
Type: Security Advisory
Severity: N/A
Issued on: 2000-11-02
Last updated on: 2000-11-02
Affected Products: Red Hat Linux 6.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2000-0186
CVE-2000-0520

Details

The Red Hat 7.0 dump is being released for Red Hat 6.x and Red Hat 5.x
in order to remove root setuid bits to prevent a known dump
exploit (#20111).

The new dump packages also include a fix for a buffer overflow (#9899)

Dump can be used to gain root access.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

Updated packages

Red Hat Linux 6.2

alpha:
ftp://updates.redhat.com/6.2/alpha/dump-0.4b19-5.6x.alpha.rpm
Missing file
    339d7bdc63a154a08ac05b2d59be299f
ftp://updates.redhat.com/6.2/alpha/dump-static-0.4b19-5.6x.alpha.rpm
Missing file
    aa4eb8d7e446cdbaf10cec1d6beb2ea8
ftp://updates.redhat.com/6.2/alpha/rmt-0.4b19-5.6x.alpha.rpm
Missing file
    d70e961e5ce712df4b671fe7fa53cf0f
 
i386:
ftp://updates.redhat.com/6.2/i386/dump-0.4b19-5.6x.i386.rpm
Missing file
    62d35595f6b11c7a478d2f3608ebb8b3
ftp://updates.redhat.com/6.2/i386/dump-static-0.4b19-5.6x.i386.rpm
Missing file
    86a7cd33b8c870f01a4fe3fc500a6af1
ftp://updates.redhat.com/6.2/i386/rmt-0.4b19-5.6x.i386.rpm
Missing file
    6f1831d60345791448f94f7e8276a47e
 
sparc:
ftp://updates.redhat.com/6.2/sparc/dump-0.4b19-5.6x.sparc.rpm
Missing file
    f907fe91725a340c07f44d381eb4da70
ftp://updates.redhat.com/6.2/sparc/dump-static-0.4b19-5.6x.sparc.rpm
Missing file
    daaf188d21fdfe8141f4e0dcfc8fa51e
ftp://updates.redhat.com/6.2/sparc/rmt-0.4b19-5.6x.sparc.rpm
Missing file
    930c7a447f5c197a73e619789a8ae18a
 

Bugs fixed (see bugzilla for more information)

20111 - RH6.2 dump SUID exploit (via RSH env. var)


References


Keywords

exploit


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/