[ GLSA 200510-22 ] SELinux PAM: Local password guessing attack

From: Thierry Carrez (koon_at_gentoo.org)
Date: 10/28/05

  • Next message: Martin Schulze: "[SECURITY] [DSA 877-1] New gnump3d packages fix several vulnerabilities"
    Date: Fri, 28 Oct 2005 13:17:04 +0200
    To: gentoo-announce@lists.gentoo.org
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200510-22
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: Normal
         Title: SELinux PAM: Local password guessing attack
          Date: October 28, 2005
          Bugs: #109485
            ID: 200510-22

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    A vulnerability in the SELinux version of PAM allows a local attacker
    to brute-force system passwords.

    Background
    ==========

    PAM (Pluggable Authentication Modules) is an architecture allowing the
    separation of the development of privilege granting software from the
    development of secure and appropriate authentication schemes. SELinux
    is an operating system based on Linux which includes Mandatory Access
    Control.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 sys-libs/pam < 0.78-r3 >= 0.78-r3

    Description
    ===========

    The SELinux patches for PAM introduce a vulnerability allowing a
    password to be checked with the unix_chkpwd utility without delay or
    logging. This vulnerability doesn't affect users who do not run
    SELinux.

    Impact
    ======

    A local attacker could exploit this vulnerability to brute-force
    passwords and escalate privileges on an SELinux system.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All SELinux PAM users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose ">=sys-libs/pam-0.78-r3"

    References
    ==========

      [ 1 ] CVE-2005-2977
            http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2977

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200510-22.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    



  • Next message: Martin Schulze: "[SECURITY] [DSA 877-1] New gnump3d packages fix several vulnerabilities"

    Relevant Pages