Solaris syslogd overflow

From: David Thiel (lx_at_redundancy.redundancy.org)
Date: 06/05/03

  • Next message: Martin: "Monkey Http Daemon"
    Date: Wed, 4 Jun 2003 16:52:18 -0659
    To: bugtraq@securityfocus.com
    
    
    

    Synopsis:

            Solaris syslogd is vulnerable to a remote buffer overflow.

    Versions:

            Solaris 2.6 SPARC: Not vulnerable
            Solaris 2.7 SPARC/x86: Untested
            Solaris 8 SPARC: Vulnerable
            Solaris 8 x86: Vulnerable
            Solaris 9 SPARC: Not vulnerable
            Solaris 9 x86: Untested
            
    Impact:

            Low-Medium.

            While I've not been able to craft an exploit that successfully
            executes arbitrary code, it may still be possible. If
            not, this can be used to hide evidence of attack or intrusion
            in environments where a central logging server is used.

    Description:

            In Solaris 8, syslogd dumps core when receiving a UDP packet
            larger than 1024 bytes, instead of truncating it, as dictated
            by RFC3164, section 6.1.

    Fix:

            Sun Microsystems released patch 110945-08 for SPARC and
            110946 for x86, which resolves this problem (identified as
            bug #4812764) on 2003-05-29. Obviously, any systems not
            using syslogd to log from remote hosts should be run with
            the -t flag. Alternatively, consider switching to a more
            reliable logging system, such as Gerrit Pape's socklog.

    Timeline:

            2003-01-18: Problem discovered, platforms tested.
            2003-01-21: Sun Security Coordination Team notified.
            2003-02-04: Sun confirms the problem and assigns bug ID.
            2003-05-29: Patch released.

    References:

            http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=110945&rev=08

    If anyone else is able to do anything more interesting with this bug,
    I'd like to hear about it.

    Cheers,
    lx

    
    


    • application/pgp-signature attachment: stored

  • Next message: Martin: "Monkey Http Daemon"

    Relevant Pages

    • Re: Random Compiler Errors, again
      ... Thanks Charles - I'll give it a try. ... Did they produce a patch to fix our ... > produced a special build of mshtml.dll to resolve a bug. ... > from dll references to project references. ...
      (microsoft.public.dotnet.general)
    • Re: Member Properties
      ... > Have you seen any references to this bug and a possible fix coming soon? ... this is the first time I see something like this. ...
      (microsoft.public.sqlserver.olap)
    • [Full-Disclosure] Solaris syslogd overflow
      ... Fix: ... Timeline: ... References: ... If anyone else is able to do anything more interesting with this bug, ...
      (Full-Disclosure)
    • Re: Member Properties
      ... No the table is fully normalized and each customer only occurs once. ... Have you seen any references to this bug and a possible fix coming soon? ...
      (microsoft.public.sqlserver.olap)
    • [Un] Unangband 0.6.3 released
      ... Allow player to assemble friendly monsters and carry eggs to hatch ... Updated druidic spells to use new region code. ... Fix lockup bugs generating the Old Forest. ... Fix bug where items dropped by monster death would infinitely ...
      (rec.games.roguelike.announce)