A locally exploitable vulnerability is present in the util-linux package
which shipped with Red Hat Linux.
[Updated 8 July 2003]
Added packages for Red Hat Linux on IBM iSeries and pSeries systems.
The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. The chfn
utility included in this package allows users to modify personal
information stored in the system-wide password file, /etc/passwd. In order
to modify this file, this application is installed setuid root.
Under certain conditions, a carefully crafted attack sequence can be
performed to exploit a complex file locking and modification race present
in this utility allowing changes to be made to /etc/passwd.
In order to successfully exploit the vulnerability and perform privilege
escalation there is a need for minimal administrator interaction.
Additionally, the password file must be over 4 kilobytes, and the local
attackers entry must not be in the last 4 kilobytes of the password file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2002-0638 to this issue.
An interim workaround is to remove setuid flags from /usr/bin/chfn and
/usr/bin/chsh. All users of Red Hat Linux should update the packages
contained in this erratum, which are patched to correct this vulnerability.
Many thanks to Michal Zalewski of Bindview for alerting us to this issue.
| Red Hat Linux 6.2 |
|
| SRPMS: |
ftp://updates.redhat.com/6.2/en/os/SRPMS/util-linux-2.10f-7.6.2.src.rpm
Missing file |
0af6265f350849394fc54ca7f006fd82 |
| |
| Alpha: |
ftp://updates.redhat.com/6.2/en/os/alpha/util-linux-2.10f-7.6.2.alpha.rpm
Missing file |
4e30115e7fd311ac8496637c03716473 |
| |
| IA-32: |
ftp://updates.redhat.com/6.2/en/os/i386/util-linux-2.10f-7.6.2.i386.rpm
Missing file |
e1c0e740d41aaddc7817604ed449e872 |
| |
| Sparc: |
ftp://updates.redhat.com/6.2/en/os/sparc/util-linux-2.10f-7.6.2.sparc.rpm
Missing file |
fe28b4c80b9fe909c38f913b899ddb16 |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
ftp://updates.redhat.com/7.0/en/os/SRPMS/util-linux-2.10m-12.7.0.src.rpm
Missing file |
4aa3502469cc8255aea825cebe82d4db |
| |
| Alpha: |
ftp://updates.redhat.com/7.0/en/os/alpha/util-linux-2.10m-12.7.0.alpha.rpm
Missing file |
b2e1b30a837e440297acba35d13fab77 |
| |
| IA-32: |
ftp://updates.redhat.com/7.0/en/os/i386/util-linux-2.10m-12.7.0.i386.rpm
Missing file |
af9aca214e81e4f306d49ed398a79f22 |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/SRPMS/util-linux-2.11f-17.7.2.src.rpm
Missing file |
dc87f0566da2f6a37443f9614cb1ff61 |
| |
| Alpha: |
ftp://updates.redhat.com/7.1/en/os/alpha/util-linux-2.11f-17.7.2.alpha.rpm
Missing file |
c3bc4100fdc6e4e7c4b524c16991f168 |
| |
| IA-32: |
ftp://updates.redhat.com/7.1/en/os/i386/util-linux-2.11f-17.7.2.i386.rpm
Missing file |
668e4b28b07dcd9718744b2c59383bc2 |
| |
| IA-64: |
ftp://updates.redhat.com/7.1/en/os/ia64/util-linux-2.11f-17.7.2.ia64.rpm
Missing file |
200e1661f445fca662f51d810f650448 |
| |
| Red Hat Linux 7.1 for iSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/iSeries/SRPMS/util-linux-2.11f-17.7.2.src.rpm
Missing file |
dc87f0566da2f6a37443f9614cb1ff61 |
| |
| iSeries: |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/util-linux-2.11f-17.7.2.ppc.rpm
Missing file |
39b2f33573da14946639e38f7dbccaec |
| |
| Red Hat Linux 7.1 for pSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/pSeries/SRPMS/util-linux-2.11f-17.7.2.src.rpm
Missing file |
dc87f0566da2f6a37443f9614cb1ff61 |
| |
| pSeries: |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/util-linux-2.11f-17.7.2.ppc.rpm
Missing file |
39b2f33573da14946639e38f7dbccaec |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
ftp://updates.redhat.com/7.2/en/os/SRPMS/util-linux-2.11f-17.7.2.src.rpm
Missing file |
dc87f0566da2f6a37443f9614cb1ff61 |
| |
| IA-32: |
ftp://updates.redhat.com/7.2/en/os/i386/util-linux-2.11f-17.7.2.i386.rpm
Missing file |
668e4b28b07dcd9718744b2c59383bc2 |
| |
| IA-64: |
ftp://updates.redhat.com/7.2/en/os/ia64/util-linux-2.11f-17.7.2.ia64.rpm
Missing file |
200e1661f445fca662f51d810f650448 |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
ftp://updates.redhat.com/7.3/en/os/SRPMS/util-linux-2.11n-12.7.3.src.rpm
Missing file |
474988909a18c0f73a65de40bf946e92 |
| |
| IA-32: |
ftp://updates.redhat.com/7.3/en/os/i386/losetup-2.11n-12.7.3.i386.rpm
Missing file |
b1b6d7852f75d1014204b7853f656427 |
ftp://updates.redhat.com/7.3/en/os/i386/mount-2.11n-12.7.3.i386.rpm
Missing file |
496ec0a9c0720ba5bed7baa917114aac |
ftp://updates.redhat.com/7.3/en/os/i386/util-linux-2.11n-12.7.3.i386.rpm
Missing file |
da8c81ee48c180694b89c9c99f543256 |
| |