|
CERT-NL | |||||
| Author/Source | : | Xander Jansen | Index | : | S-00-08 | |
| Distribution | : | World | Page | : | 1 | |
| Classification | : | External | Version | : | 1 | |
| Subject | : | SGI IRIX fam service Vulnerability | Date | : | 04-Mar-2000 | |
By courtesy of Silicon Graphics we received information on a vulnerability in the SGI
IRIX fam service allowing remote users acces to local information.
CERT-NL recommends to follow the steps outlined below.
SGI Security Advisory
Title: fam Vulnerability Title: NAI-0016: Silicon Graphics IRIX fam service Number: 20000301-01-I Date: March 1, 2000
SGI provides this information freely to the SGI user community for its consideration, interpretation, implementation and use. SGI recommends that this information be acted upon as soon as possible.
SGI provides the information in this Security Advisory on an "AS-IS" basis only, and disclaims all warranties with respect thereto, express, implied or otherwise, including, without limitation, any warranty of merchantability or fitness for a particular purpose. In no event shall SGI be liable for any loss of profits, loss of business, loss of data or for any indirect, special, exemplary, incidental or consequential damages of any kind arising from your use of, failure to use or improper use of any of the instructions or information in this Security Advisory.
As a followup to the NAI Advisory #16: "Silicon Graphics IRIX fam service", SGI has investigated and has open sourced fam which includes the fix to this vulnerability.
| Issue Specifics |
The fam daemon is an RPC server that tracks changes to the filesystem.
NAI has reported that a vulnerability has been discovered in fam which allows an attacker to learn the names of files and directories on IRIX systems.
SGI has investigated the issue and recommends the following steps for neutralizing the exposure. It is recommended that these measures be implemented on all vulnerable SGI systems running the fam service.
| Impact |
The fam daemon is installed by default on all versions of IRIX 5.X and IRIX 6.X.
A local user account on the vulnerable system is not required in order to exploit the fam daemon.
The vulnerability can be exploited remotely by using carefully crafted RPC packets that are sent to the fam daemon.
The vulnerability leads to unauthorized access to the names of files and directories on an IRIX system.
This vulnerability was reported by Network Associates, Inc. in Advisory NAI-0016:
http://www.nai.com/nai_labs/asp_set/advisory/16_fam_adv.asp
This vulnerability has been publicly discussed in Usenet newsgroups and mailing lists.
| Temporary Solution |
Although a version of fam which fixes this vulnerability is available as open source, it is realized that there may be situations where compiling and installing the new version may not be possible.
The steps below can be used to disable the fam daemon.
**** WARNING **** Disabling fam daemon will impact and/or disable applications that use the RPC-based fam daemon. This includes fm, mailbox, mediad, scanners, sysmon , fxbuilder, IRIS Annotator and applications like MediaMail that linked with the libfam.a static library.
- Become the root user on the system.
% /bin/su - Password: #- Comment out the fam service in /etc/inetd.conf
# vi /etc/ined.confChange the line:
sgi_fam/1 stream rpc/tcp wait root ?/usr/etc/fam famTo:
#sgi_fam/1 stream rpc/tcp wait root ?/usr/etc/fam famand save the file.
- Restart inetd..
# /etc/killall -HUP inetd- Kill any running fam daemon
NOTE: This may disable applications that use fam including MediaMail.# /etc/killall fam- Return to previous level.
# exit %
Solution SGI has open sourced the fam daemon and the source code is available from:
http://oss.sgi.com/projects/fam/The open source version of fam has a fix for this vulnerability.
Patches are being built for currently supported IRIX operating systems and this advisory will be updated when these patches are made available.
The fam vulnerability is scheduled to be fixed in IRIX 6.5.8
Acknowledgments SGI wishes to thank the Network Associates, Inc. for their assistance in this matter.
SGI Security Information/Contacts If there are questions about this document, email can be sent to cse-security-alert@sgi.com.
------oOo------
CERT-NL is the Computer Emergency Response Team for SURFnet customers. SURFnet is the Dutch network for educational, research and related institutes. CERT-NL is a member of the Forum of Incident Response and Security Teams (FIRST).
All CERT-NL material is available under:
http://cert.surfnet.nl/
In case of computer or network security problems please contact your local CERT/security-team or CERT-NL (if your institute is NOT a SURFnet customer please address the appropriate (local) CERT/security-team).
CERT-NL is one/two hour(s) ahead of UTC
(GMT) in winter/summer,
i.e. UTC+0100 in winter and UTC+0200 in summer (DST).
| Email: | cert-nl@surfnet.nl | ATTENDED REGULARLY ALL DAYS |
| Phone: | +31 302 305 305 | BUSINESS HOURS ONLY |
| Fax: | +31 302 305 329 | BUSINESS HOURS ONLY |
| Snailmail: | SURFnet bv Attn. CERT-NL P.O. Box 19035 NL - 3501 DA UTRECHT The Netherlands |
. |
NOODGEVALLEN: 06 22 92 35 64 ALTIJD
BEREIKBAAR
EMERGENCIES : +31 6 22 92 35 64 ATTENDED AT ALL TIMES
CERT-NL'S EMERGENCY PHONENUMBER IS ONLY TO BE USED IN CASE OF EMERGENCIES:
THE SURFNET HELPDESK OPERATING THE EMERGENCY NUMBER HAS A *FIXED* PROCEDURE FOR DEALING
WITH YOUR ALERT AND WILL IN REGULAR CASES RELAY IT TO CERT-NL IN AN APPROPRIATE MANNER.
CERT-NL WILL THEN CONTACT YOU.
|
|||||||