[UNIX] Red Hat 7.2 GnuPG signed RPM verification fails on distribution files
From: support@securiteam.comDate: 10/23/01
- Previous message: support@securiteam.com: "[NEWS] Mac OS X 10.1 Local Security Exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Subject: [UNIX] Red Hat 7.2 GnuPG signed RPM verification fails on distribution files Message-Id: <20011023183302.E2204138BF@mail.der-keiler.de> Date: Tue, 23 Oct 2001 20:33:02 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Red Hat 7.2 GnuPG signed RPM verification fails on distribution files
------------------------------------------------------------------------
SUMMARY
Red Hat 7.2 distribution files on popular ftp sites such as
ftp.ibiblio.org and mirrors.hpcf.upr.edu are not signed. It is unlikely
that this is an attack as the number of sites involved makes it likely
someone would have noticed and notified the community. Either Red Hat did
not sign these packages, or someone subverted the distribution process
before the files got to various sites. For Red Hat 7.1 please note that
all files were correctly signed with the Red Hat GnuPG security key.
DETAILS
Vulnerable systems:
Red Hat version 7.2
Immune systems:
Red Hat version 7.1 and prior
Impact:
An attacker can create RPM's that will not appear any different from the
real ones, as they do not need to be signed. Finding the MD5 sums of the
files in trusted locations is very difficult.
Red Hat has released Red Hat 7.2, a much-anticipated release. Typically,
all the rpm distribution files are signed, making it very easy to verify
their correctness. Since numerous packages are not signed, it becomes
trivial for an attacker to replace packages on a distribution site with no
one being able to easily verify that they have been subverted. An attacker
would not even need to modify or add files to the package, instead they
could add a preinstall, postinstall, preuninstall, or postuninstall script
that would be capable of compromising the system since these scripts run
with root privileges. Packages include rpmdb-redhat and redhat-release.
Solutions and workarounds:
None available. Red Hat needs to sign the packages properly with GnuPG.
ADDITIONAL INFORMATION
The information has been provided by <mailto:kurt@seifried.org> Kurt
Seifried.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Mac OS X 10.1 Local Security Exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [Full-Disclosure] [RHSA-2003:064-01] Updated XFree86 4.1.0 packages are available
... security vulnerabilities have been found and fixed. ... other bug fixes,
driver updates, and other enhancements have been made. ... Xterm, provided as part of the XFree86
packages, provides an escape ... Please note that this update is also available via Red
Hat Network. ... (Full-Disclosure) - [Full-Disclosure] [RHSA-2004:166-01] Updated kernel packages resolve security vulnerabilities
... Updated kernel packages that fix several minor security vulnerabilities are
... where is a list of the RPMs you wish to upgrade. ... Please note that this update
is also available via Red Hat Network. ... (Full-Disclosure) - Re: Security rankings
... > shows that Linux consistently tops Microsoft Windows in terms of security.
... Instead of being emotional about it I cite facts and findings ... After searching
for "Red Hat" I ... (microsoft.public.security) - Red Hat 7.2 GnuPG signed RPM verification fails on distribution files
... Red Hat 7.2 GnuPG signed RPM verification fails on distribution files
... Either Red Hat did not sign these packages, ... (Bugtraq) - Re: Upgrading RH9 to Fedora?
... >for patches or security fixes, my impression is that they will release the ...
>latest stable with the appropriate fixes as opposed to backporting. ... Internet-based
support. ... Now Red Hat has pulled out entirely, while forcing the former "Red Hat
... (comp.os.linux.misc)