Vulnerability Assessment & Network Security Forums
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.
Vulnerability Assessment Details
Check for the version of the util packages
Detailed Explanation for this Vulnerability Assessment
The util-linux package shipped with Red Hat Linux Advanced Server contains
a locally exploitable vulnerability.
The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. The 'chfn'
utility included in this package permits users to modify personal
information stored in the system-wide password file, /etc/passwd. In order
to modify this file, this application is installed setuid root.
Under certain conditions, a carefully crafted attack sequence can be
performed to exploit a complex file locking and modification race present
in this utility permiting changes to be made to /etc/passwd.
In order to successfully exploit the vulnerability and perform privilege
escalation there is a need for a minimal administrator interaction.
Additionally, the password file must be over 4 kilobytes, and the local
attackers entry must not be in the last 4 kilobytes of the password file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2002-0638 to this issue.
An interim workaround is to remove setuid flags from /usr/bin/chfn and
/usr/bin/chsh. All users of Red Hat Linux should update to the errata
util-linux packages which contain a patch to correct this vulnerability.
Many thanks to Michal Zalewski of Bindview for alerting us to this issue.
Solution : http://rhn.redhat.com/errata/RHSA-2002-137.html
Network Security Threat Level: High
Networks Security ID:
Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security
|INTEL XEON 6 CORE SR1AJ PROCESSOR E5-2420V2 2.2GHZ KIT
|DELL POWEREDGE R630 8 BAY E5-2603V4 1.7GHZ 32GB 7 X 2TB SAS 12G H730
|DELL POWEREDGE R630 10 BAY TWO E5-2697V3 2.6GHZ 128GB 1.6TB SSD SAS H330
|DELL POWEREDGE R630 10 BAY TWO E5-2637V4 3.5GHZ 192GB 4 X 300GB 15K SAS H330
No Discussions have been posted on this vulnerability.