|
_____________________________________________________ The Computer Incident Advisory Capability ___ __ __ _ ___ / | / \ / \___ __|__ /___\ \___ _____________________________________________________ Information Bulletin July 8, 1991, 1100 PDT Number B-32 ________________________________________________________________________ PROBLEM: Bug in /usr/bin/mail may allow users unauthorized access to a root shell PLATFORM: DEC VAX and RISC (DECStation and DECSystem) computers running versions of Ultrix prior to 4.2. DAMAGE: Potential for significant damage to system and unauthorized access to users' files once an intruder has gained root access. SOLUTIONS: Patch available through DEC Customer Support Center (1-800-332-8000) or CIAC. ________________________________________________________________________ Critical Facts about /usr/bin/mail Security Problem A recently discovered bug in Ultrix /usr/bin/mail may allow a non-privileged user to obtain unauthorized access to a root shell. This problem applies to all Ultrix versions prior to 4.2 running on both the VAX and DEC RISC (i.e. DECStation and DECSystem) architectures. DEC has determined that the /usr/bin/mail program provided in Ultrix 4.2 does not contain this bug, and is compatible with Ultrix 4.1 systems. However, version 4.2 of /usr/bin/mail has not been shown to be compatible with versions of Ultrix previous to Ultrix version 4.1; upgrading to Ultrix 4.2 or upgrading to Ultrix 4.1 and using the Ultrix 4.2 /usr/bin/mail program is required to eliminate this bug in these older versions of Ultrix. To update an Ultrix 4.1 system, you must first obtain the Ultrix 4.2 binary of /usr/bin/mail for your computer's architecture from DEC, CIAC, or another compatible Ultrix 4.2 system and store it in a temporary location (e.g., /tmp/mail). Next, use the following procedure: (Login as root - you must have root privilege to make this update.) # cd /usr/bin # mv mail mail-4.1 # chmod 600 mail-4.1 (Copy the Ultrix 4.2 binary to /usr/bin/mail, e.g., mv /tmp/mail /usr/bin/mail) # chown root mail # chgrp kmem mail # chmod 6755 mail For additional information or assistance, please contact CIAC Hal Brand (415) 422-6312 or (FTS) 532-6312 brand@addvax.llnl.gov Call CIAC at (415) 422-8193 or (FTS) 532-8193 or send e-mail to ciac@cheetah.llnl.gov. Send FAX messages to: (415) 423-0913 or (FTS) 543-0913. Tsutomu Shimomura and Digital Equipment Corportation (DEC) provided some of the information contained in this bulletin. Neither the United States Government nor the University of California nor any of their employees, makes any warranty, expressed or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed, or represents that its use would not infringe privately owned rights. Reference herein to any specific commercial products, process, or service by trade name, trademark manufacturer, or otherwise, does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government or the University of California. The views and opinions of authors expressed herein do not necessarily state or reflect those of the United States Government nor the University of California, and shall not be used for advertising or product endorsement purposes.