TUCoPS :: Linux :: Red Hat/Fedora :: n-056.txt

Red Hat 2.4 Kernel ptrace Vulnerability (CIAC N-056)

             __________________________________________________________

                       The U.S. Department of Energy
                   Computer Incident Advisory Capability
                           ___  __ __    _     ___
                          /       |     /_\   /
                          \___  __|__  /   \  \___
             __________________________________________________________

                             INFORMATION BULLETIN

            Red Hat Updated 2.4 Kernel Fix for ptrace Vulnerability
                               [RHSA-2003:098-24]

March 18, 2003 14:00 GMT                                          Number N-056
[Revised 02 June 2003]
______________________________________________________________________________
PROBLEM:       The Linux kernel handles the basic functions of the operating 
               system. A vulnerability has been found in version 2.4.18 of the 
               kernel. These packages fix a ptrace-related vulnerability that 
               can lead to elevated (root) privileges. 
PLATFORM:      Red Hat Linux 7.1 
               Red Hat Linux 7.2 
               Red Hat Linux 7.3 
               Red Hat Linux 8.0 
DAMAGE:        If exploited, a local user could gain root access. 
SOLUTION:      Apply updated packages as stated in Red Hat's advisory. 
______________________________________________________________________________
VULNERABILITY  The risk is MEDIUM. This vulnerability allows local users to 
ASSESSMENT:    gain root privileges by using ptrace to attach to a child 
               process that is spawned by the kernel. 
______________________________________________________________________________
LINKS: 
 CIAC BULLETIN:      http://www.ciac.org/ciac/bulletins/n-056.shtml 
 ORIGINAL BULLETIN:  https://rhn.redhat.com/errata/RHSA-2003-098.html 
______________________________________________________________________________

Revision History: Updated kernel packages for Red Hat Linux 7.1, 7.2, 7.3, 
and 8.0 are now available.

[***** Start RHSA-2003:098-24 *****]

Updated 2.4 kernel fixes vulnerability

Advisory: RHSA-2003:098-24 
Last updated on: 2003-06-02 
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0 
CVEs (cve.mitre.org): CAN-2003-0127

Security Advisory 


Details:

Updated kernel packages for Red Hat Linux 7.1, 7.2, 7.3, and 8.0 are now
available. These packages fix a ptrace-related vulnerability that can
lead to elevated (root) privileges.

[Updated 30 March 2003]
Updated kernel packages for Red Hat Linux 7.2 ia64 have been added.

[Updated 28 May 2003]
Replacement kernel packages for Red Hat Linux 7.2 ia64 have been added; the
previous packages did not contain the fix for the ptrace vulnerability.

The Linux kernel handles the basic functions of the operating system.

A vulnerability has been found in version 2.4.18 of the kernel. This
vulnerability makes it possible for local users to gain elevated (root)
privileges without authorization. This advisory includes updates for
Red Hat Linux 7.1, 7.2, 7.3, and 8.0.

All users of Red Hat Linux 7.1, 7.2, 7.3, and 8.0 should upgrade to
these errata packages, which contain patches to fix the vulnerability.


Updated packages:

Red Hat Linux 7.1 

--------------------------------------------------------------------------------
 
SRPMS: 
kernel-2.4.18-27.7.x.src.rpm
File outdated by:  RHSA-2003:187     addeef535e3590c9c080661b6747c3a8 
  
athlon: 
kernel-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     f604974008bc2f85ddb83edcbd137f08 
kernel-smp-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     87298e818938d0db069030f2737a83c1 
  
i386: 
kernel-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     d8d7ad334e192989308399924cbf91f8 
kernel-BOOT-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     2060403022a1dc25a5700356d2d6b649 
kernel-doc-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     02ae46618c1b001874e1330ad57f54fa 
kernel-source-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     b169f55fef2064ef29c753674aaba9b0 
  
i586: 
kernel-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     5a970002916eebe2e6665fbbf0a44109 
kernel-smp-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     b3fb5228466e86dfb9287c32b89b8118 
  
i686: 
kernel-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     cab59b8ce75e659243340b811a0e59ad 
kernel-bigmem-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     5ceca1d559294ba1dee9dcf807a0e442 
kernel-debug-2.4.18-27.7.x.i686.rpm
[ via FTP ] [ via HTTP ]             007688dc1826fee8abaff646ea77cedc 
kernel-smp-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     53187f3f166aa6e5a500b106d6bff69c 
  
Red Hat Linux 7.2 

--------------------------------------------------------------------------------
 
SRPMS: 
kernel-2.4.18-27.7.x.src.rpm
File outdated by:  RHSA-2003:187     addeef535e3590c9c080661b6747c3a8 
kernel-2.4.9-45.src.rpm
[ via FTP ] [ via HTTP ]             f02b540d039656fd187f978cbd5019a5 
  
athlon: 
kernel-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     f604974008bc2f85ddb83edcbd137f08 
kernel-smp-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     87298e818938d0db069030f2737a83c1 
  
i386: 
kernel-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     d8d7ad334e192989308399924cbf91f8 
kernel-BOOT-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     2060403022a1dc25a5700356d2d6b649 
kernel-doc-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     02ae46618c1b001874e1330ad57f54fa 
kernel-source-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     b169f55fef2064ef29c753674aaba9b0 
  
i586: 
kernel-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     5a970002916eebe2e6665fbbf0a44109 
kernel-smp-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     b3fb5228466e86dfb9287c32b89b8118 
  
i686: 
kernel-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     cab59b8ce75e659243340b811a0e59ad 
kernel-bigmem-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     5ceca1d559294ba1dee9dcf807a0e442 
kernel-debug-2.4.18-27.7.x.i686.rpm
[ via FTP ] [ via HTTP ]             007688dc1826fee8abaff646ea77cedc 
kernel-smp-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     53187f3f166aa6e5a500b106d6bff69c 
  
ia64: 
kernel-2.4.9-45.ia64.rpm
[ via FTP ] [ via HTTP ]             1d1a5f8df83abfe997ce85d157c65ff1 
kernel-doc-2.4.9-45.ia64.rpm
[ via FTP ] [ via HTTP ]             1dd2a98bcf0c020545d4a79bdf1718ab 
kernel-smp-2.4.9-45.ia64.rpm
[ via FTP ] [ via HTTP ]             a0606de442a7ffbfc1fca2191e3dab5d 
kernel-source-2.4.9-45.ia64.rpm
[ via FTP ] [ via HTTP ]             b51b363b46abc1f3d530902a2583f9f2 
  
Red Hat Linux 7.3 

--------------------------------------------------------------------------------
 
SRPMS: 
kernel-2.4.18-27.7.x.src.rpm
File outdated by:  RHSA-2003:187     addeef535e3590c9c080661b6747c3a8 
  
athlon: 
kernel-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     f604974008bc2f85ddb83edcbd137f08 
kernel-smp-2.4.18-27.7.x.athlon.rpm
File outdated by:  RHSA-2003:187     87298e818938d0db069030f2737a83c1 
  
i386: 
kernel-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     d8d7ad334e192989308399924cbf91f8 
kernel-BOOT-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     2060403022a1dc25a5700356d2d6b649 
kernel-doc-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     02ae46618c1b001874e1330ad57f54fa 
kernel-source-2.4.18-27.7.x.i386.rpm
File outdated by:  RHSA-2003:187     b169f55fef2064ef29c753674aaba9b0 
  
i586: 
kernel-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     5a970002916eebe2e6665fbbf0a44109 
kernel-smp-2.4.18-27.7.x.i586.rpm
File outdated by:  RHSA-2003:187     b3fb5228466e86dfb9287c32b89b8118 
  
i686: 
kernel-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     cab59b8ce75e659243340b811a0e59ad 
kernel-bigmem-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     5ceca1d559294ba1dee9dcf807a0e442 
kernel-debug-2.4.18-27.7.x.i686.rpm
[ via FTP ] [ via HTTP ]             007688dc1826fee8abaff646ea77cedc 
kernel-smp-2.4.18-27.7.x.i686.rpm
File outdated by:  RHSA-2003:187     53187f3f166aa6e5a500b106d6bff69c 
  
Red Hat Linux 8.0 

--------------------------------------------------------------------------------
 
SRPMS: 
kernel-2.4.18-27.8.0.src.rpm
File outdated by:  RHSA-2003:187     1eca60a3b18951dc74a0d4e59eafea69 
  
athlon: 
kernel-2.4.18-27.8.0.athlon.rpm
File outdated by:  RHSA-2003:187     097df4f27af2703a8332d136b6a87db4 
kernel-smp-2.4.18-27.8.0.athlon.rpm
File outdated by:  RHSA-2003:187     5ecb81df3091f5fec327d789643b973d 
  
i386: 
kernel-2.4.18-27.8.0.i386.rpm
File outdated by:  RHSA-2003:187     05152635e760b2f15b21e343da99ddf4 
kernel-BOOT-2.4.18-27.8.0.i386.rpm
File outdated by:  RHSA-2003:187     2c737942e4ea911d58b87fcc5a22eece 
kernel-doc-2.4.18-27.8.0.i386.rpm
File outdated by:  RHSA-2003:187     0d45350f1bc10a45698ca517b2683869 
kernel-source-2.4.18-27.8.0.i386.rpm
File outdated by:  RHSA-2003:187     6db233f9749ca25b3fff2073aa0afaea 
  
i586: 
kernel-2.4.18-27.8.0.i586.rpm
File outdated by:  RHSA-2003:187     c6f8aba34d85c7447ab4c2c1ab90e7f2 
kernel-smp-2.4.18-27.8.0.i586.rpm
File outdated by:  RHSA-2003:187     80d3cff38bd8d535bbe239a5958730af 
  
i686: 
kernel-2.4.18-27.8.0.i686.rpm
File outdated by:  RHSA-2003:187     4c0fc846e4faeab3e2e1b966aa65d945 
kernel-bigmem-2.4.18-27.8.0.i686.rpm
File outdated by:  RHSA-2003:187     d138caa438cc87fc6835da69626a1602 
kernel-debug-2.4.18-27.8.0.i686.rpm
[ via FTP ] [ via HTTP ]             ad41c60b306912c33a4b050511eec08c 
kernel-smp-2.4.18-27.8.0.i686.rpm
File outdated by:  RHSA-2003:187     c5e17489cee52cd526ebac66604a22ba 
 

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied, especially the additional
packages from RHSA-2002:205 and RHSA-2002:206.

The procedure for upgrading the kernel manually is documented at:

http://www.redhat.com/support/docs/howto/kernel-upgrade/

Please read the directions for your architecture carefully before
proceeding with the kernel upgrade.

Please note that this update is also available via Red Hat Network. Many
people find this to be an easier way to apply updates. To use Red Hat
Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system. Note that you need to select the kernel
explicitly on default configurations of up2date.


References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0127

Keywords:

ptrace 

--------------------------------------------------------------------------------
The listed packages are GPG signed by Red Hat, Inc. for security. Our key is 
available at: http://www.redhat.com/solutions/security/news/publickey/#key 
You can verify each package and see who signed it with the following command:

rpm --checksig -v filename 
If you only wish to verify that each package has not been corrupted or tampered 
with, examine only the md5sum with the following command:

md5sum filename 
The Red Hat security contact is security@redhat.com. More contact details at 
http://www.redhat.com/solutions/security/news/contact.html

[***** End RHSA-2003:098-24 *****]

_______________________________________________________________________________

CIAC wishes to acknowledge the contributions of Red Hat Inc. for the
information contained in this bulletin.
_______________________________________________________________________________

CIAC, the Computer Incident Advisory Capability, is the computer
security incident response team for the U.S. Department of Energy
(DOE) and the emergency backup response team for the National
Institutes of Health (NIH). CIAC is located at the Lawrence Livermore
National Laboratory in Livermore, California. CIAC is also a founding
member of FIRST, the Forum of Incident Response and Security Teams, a
global organization established to foster cooperation and coordination
among computer security teams worldwide.

CIAC services are available to DOE, DOE contractors, and the NIH. CIAC
can be contacted at:
    Voice:    +1 925-422-8193 (7x24)
    FAX:      +1 925-423-8002
    STU-III:  +1 925-423-2604
    E-mail:   ciac@ciac.org

Previous CIAC notices, anti-virus software, and other information are
available from the CIAC Computer Security Archive.

   World Wide Web:      http://www.ciac.org/
   Anonymous FTP:       ftp.ciac.org

PLEASE NOTE: Many users outside of the DOE, ESnet, and NIH computing
communities receive CIAC bulletins.  If you are not part of these
communities, please contact your agency's response team to report
incidents. Your agency's team will coordinate with CIAC. The Forum of
Incident Response and Security Teams (FIRST) is a world-wide
organization. A list of FIRST member organizations and their
constituencies can be obtained via WWW at http://www.first.org/.

This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.

LAST 10 CIAC BULLETINS ISSUED (Previous bulletins available from CIAC)

N-046: Multiple Vulnerabilities in Oracle Servers
N-047: Microsoft Windows ME Help and Support Center Vulnerability
N-048: SendMail MTA Vulnerability
N-049: Snort RPC Preprocessing Vulnerability
N-050: Sun sendmail(1M) ".forward" Constructs Vulnerability
N-051: Red Hat Updated OpenSSL Packages Fix Timing Attack
N-052: PeopleSoft PeopleTools Remote Command Execution Vulnerability
N-053: Increased Activity Targeting Microsoft Windows Shares
N-054: Unchecked Buffer in Windows Component Could Cause Web Server Compromise
N-055: Samba smbd Buffer Overrun Vulnerability


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH