Of possible concern for our Sun users.
kas
-- Karen Ann Smith karenann@unm.edu Director, NMR Facility Adj. Asst. Prof. Dept. of Chemistry Clark Hall University of New Mexico Albuquerque, NM 87131 505.277.4031 url: http://www.unm.edu/~karenann Join SETI for an out-of-this-world screen. http://setiathome.ssl.berkeley.edu/ May you celebrate the Winter Solstice season with joy and happiness according to your own customs. --------------918ECDAC45BF327252A96BF8 Content-Type: message/rfc822 Content-Transfer-Encoding: 7bit Content-Disposition: inlineReturn-Path: <owner-security-managers@list.unm.edu> Received: from lyra.unm.edu(localhost[127.0.0.1]) (7538 bytes) by lyra.unm.edu via sendmail with P:smtp/D:altuser/T:local (sender: <owner-security-managers@list.unm.edu> owner: <real-karenann>) id <m11w7o1-0001D0C@lyra.unm.edu> for <<karenann@unm.edu>>; Thu, 9 Dec 1999 10:56:41 -0700 (MST) (Smail-3.2.0.101 1997-Dec-17 #1 built 1999-Oct-14) Resent-Message-Id: <m11w7o1-0001D0C@lyra.unm.edu> Resent-Date: Thu, 9 Dec 1999 10:56:41 -0700 (MST) Received: from mlx2.unm.edu([129.24.8.188]) (6997 bytes) by lyra.unm.edu via sendmail with P:smtp/D:aliases_listserv/T:pipe (sender: <dave@unm.edu>) id <m11w7nW-0001Cxa@lyra.unm.edu> for <security-managers@list.unm.edu>; Thu, 9 Dec 1999 10:56:10 -0700 (MST) (Smail-3.2.0.101 1997-Dec-17 #1 built 1999-Oct-14) Received: (qmail 27867 invoked by uid 27593); 9 Dec 1999 17:56:09 -0000 Received: (qmail 27862 invoked from network); 9 Dec 1999 17:56:09 -0000 Received: from ben13.unm.edu (129.24.8.113) by mlx2.unm.edu with SMTP; 9 Dec 1999 17:56:09 -0000 Message-Id: <Pine.LNX.3.95.991209120311.7284A-100000@arden.iss.net> Date: Thu, 9 Dec 1999 12:04:33 -0500 (EST) Reply-To: security-managers@list.unm.edu Sender: owner-security-managers@list.unm.edu From: X-Force <xforce@iss.net> To: alert@iss.net Subject: ISSalert: ISS Security Advisory: Buffer Overflow in Solaris Snoop Resent-To: security-managers@unm.edu MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Resent-From: "David Grisham CIRT Security Admin." <dave@unm.edu> X-Sender: owner-alert@iss.net X-Received: (qmail 27594 invoked by uid 5097); 9 Dec 1999 17:20:56 -0000 X-Received: (qmail 27587 invoked from network); 9 Dec 1999 17:20:56 -0000 X-Received: from phoenix.iss.net (HELO iss.net) (208.21.0.13) by mlx2.unm.edu with SMTP; 9 Dec 1999 17:20:56 -0000 X-Received: (qmail 5903 invoked by alias); 9 Dec 1999 17:10:24 -0000 X-Received: (qmail 5900 invoked by alias); 9 Dec 1999 17:10:23 -0000 X-Received: (qmail 5895 invoked by uid 15); 9 Dec 1999 17:10:23 -0000 X-Loop: alert X-Listprocessor-Version: 8.1 -- ListProcessor(tm) by CREN
TO UNSUBSCRIBE: email "unsubscribe alert" in the body of your message to majordomo@iss.net Contact alert-owner@iss.net for help with any problems! ---------------------------------------------------------------------------
-----BEGIN PGP SIGNED MESSAGE-----
ISS Security Advisory December 9, 1999
Buffer Overflow in Solaris Snoop
Synopsis:
Internet Security Systems (ISS) X-Force has discovered a remotely exploitable buffer overflow condition in the Solaris Snoop application. Snoop is a network sniffing tool that ships with all Solaris 2.x operating systems. It is designed to monitor all network traffic on the host's physical link by putting the machine's Ethernet interface into promiscuous mode. The buffer overflow occurs when Snoop analyzes specific types of RPC requests. When Snoop is decoding GETQUOTA requests to the rquotad RPC service and certain arguments are too long, a buffer overflow can occur. The rquotad service is used to return quotas for a user of a local file system that is mounted by a remote machine over NFS. This overflow allows a knowledgeable attacker to seize control of the Snoop application.
Description:
This buffer overflow allows a remote attacker to gain privileged access to machines running the Solaris operating system while using Snoop. This vulnerability also allows an attacker to bypass security measures in place by Solaris based firewall machines. It is not recommended to use a sniffing tool such as Snoop from a firewall to diagnose network problems.
By default, Snoop puts one or more of the machine's Ethernet interfaces into promiscuous mode. Attackers could use a tool such as AntiSniff <http://www.l0pht.com/antisniff> to locate these machines. A machine running Snoop with promiscuous mode disabled is still vulnerable to this buffer overflow and it is impossible to remotely detect Snoop's presence.
Affected Versions:
Solaris 2.4, 2.5, 2.5.1, 2.6, and 2.7 were tested and found to be vulnerable.
Recommendations:
Sun Microsystems has provided patches for all affected versions at: http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-license&nav=pub-patches.
ISS X-Force recommends verifying the existence of the vulnerability through the use of System Scanner. For additional information, please visit the following URL: http://www.iss.net/prod/ss.php3.
To download the check for System Scanner Version 3 Solaris Agent go to the following URL: http://www.iss.net/support/flexchecks/sscanner.php.
Sun Microsystems is issuing Security Bulletin #00190 regarding this vulnerability. This bulletin will be posted on Friday, December 10, 1999 at: http://sunsolve.sun.com/pub-cgi/secBulletin.pl.
Additional Information:
This vulnerability was discovered and researched by the ISS X-Force with assistance from Daniel Burnham of the ISS Professional Services Organization. ISS X-Force would like to thank Sun Microsystems for their response and handling of this vulnerability.
- ------ About ISS:
ISS is the pioneer and leading provider of adaptive network security software delivering enterprise-wide information protection solutions. ISS' award-winning SAFEsuite family of products enables information risk management within intranet, extranet and electronic commerce environments. By combining proactive vulnerability detection with real-time intrusion detection and response, ISS' adaptive security approach creates a flexible cycle of continuous security improvement, including security policy implementation and enforcement. ISS SAFEsuite solutions strengthen the security of existing systems and have dramatically improved the security posture for organizations worldwide, making ISS a trusted security advisor for firms in the Global 2000, 21 of the 25 largest U.S. commercial banks and over 35 governmental agencies. For more information, call ISS at 678-443-6000 or 800-776-2362 or visit the ISS Web site at www.iss.net.
Copyright (c) 1999 by Internet Security Systems, Inc.
Permission is hereby granted for the redistribution of this Alert electronically. It is not to be edited in any way without express consent of the X-Force. If you wish to reprint the whole or any part of this Alert in any other medium excluding electronic medium, please e-mail xforce@iss.net for permission.
Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.
X-Force PGP Key available at: http://xforce.iss.net/sensitive.php3 as well as on MIT's PGP key server and PGP.com's key server.
Please send suggestions, updates, and comments to: X-Force xforce@iss.net of Internet Security Systems, Inc.
-----BEGIN PGP SIGNATURE----- Version: 2.6.3a Charset: noconv
iQCVAwUBOE/W/zRfJiV99eG9AQGnpwP/TTFms3MCXCL2jDTWuKp5tZo7ZHZLmsyB +xfUf4BFy7f0EeFN/Z/KCptzKxG0295f9xoXdt8/wMa5wbGeBAD9i6/UF2NeNIZM 09kAcKnsmgEi17MgihypLc8Qo/ihnclMXzPfgSikpuk/5CDlsR8IkDLPMikjrXp2 4IJ2qW/bZb0= =8zxq -----END PGP SIGNATURE-----
--------------918ECDAC45BF327252A96BF8--