SuSE: cvs Double free vulnerability
Summary
______________________________________________________________________________
SuSE Security Announcement
Package: cvs
Announcement-ID: SuSE-SA:2003:0007
Date: Wednesday, Jan 22th 2003 08:30 MET
Affected products: 7.1, 7.2, 7.3, 8.0, 8.1
SuSE Linux Database Server
SuSE eMail Server 3.1
SuSE eMail Server III
SuSE Firewall Adminhost VPN
SuSE Linux Admin-CD for Firewall
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7
SuSE Linux Connectivity Server
SuSE Linux Enterprise Server 8
SuSE Linux Office Server
Vulnerability Type: remote system compromise
Severity (1-10): 3
SuSE default package: no
Cross References: CAN-2003-0015
Content of this advisory:
1) security vulnerability resolved:
- double free()
- removed dangerous features
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- libmcrypt
- gfxboot
- mod_php4
- wget
- IMP
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
CVS (Concurrent Versions System) is a version control system which
helps to manage concurrent editing of files by various authors.
Stefan Esser of e-matters reported a "double free" bug in CVS
server code for handling directory requests. This free() call allows
an attacker with CVS read access to compromise a CVS server.
Additionally two features ('Update-prog' and 'Checkin-prog') were
disabled to stop clients with write access to execute arbitrary code
on the server. These features may be configurable at run-time in future
releases of CVS server.
There is no temporary fix known other then disable public access to the
CVS server. You do not need to update the cvs package as long as you
need 'Update-prog' and 'Checkin-prog' feature and work in a trusted
environment.
Otherwise install the new packages from our FTP servers please.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
Intel i386 Platform:
SuSE-8.1:
39c4b7d43dbfed5dbc4e1cff6703929d
patch rpm(s):
c8986430a0f01c0ccc7fd2795769cb42
source rpm(s):
7aaa5bbd5740f0645307e905faddb748
SuSE-8.0:
e575a12fed87ff0bfb0fb4a62d720ce6
patch rpm(s):
97c13a4d400c28dbbbbf4f1b65f11ec7
source rpm(s):
c977c2986c677e8489f5170fcef96945
SuSE-7.3:
0b68cab2f1d7f01570932789c0ec6719
source rpm(s):
35ab94986627b96962bada1fc9998b88
SuSE-7.2:
56933c0d5cb7d5e3c419dcfde9f4359f
source rpm(s):
f997358538750a4fe856e4ef08c9282a
SuSE-7.1:
e268ef72120bbe32dd8f9de2a147cd35
source rpm(s):
6cbbdc648d0f92fb9bdaef0768393596
Sparc Platform:
SuSE-7.3:
d844d36f87a1314c5e9e0cef0c5c5e74
source rpm(s):
156571c1dffc05ecab860311397c71c6
AXP Alpha Platform:
SuSE-7.1:
674d08dd948ec15f3b7bb9a6efbbf802
source rpm(s):
65329bf424c02268d6b6c93a351f816c
PPC Power PC Platform:
SuSE-7.3:
3bbc332aa35da69e6fcaa60c4f085e72
source rpm(s):
e0fbe772152cb24a0d0ee2921432d89d
SuSE-7.1:
fdcdabeaf8be8cd78ac8ddab2d17cf61
source rpm(s):
e58e5376fccfd6d00abbe1187b813e78
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- libmcrypt
Several buffer overflows in libmcrypt were discovered by Ilia
Alshanetsky. The buffer overflows can lead to system compromise.
New packages are currently being build.
- gfxboot
Since SuSE 8.1 the bootloader lilo is replaced by grub.
Grub's password authentication can be bypassed.
New packages will be released soon.
- mod_php4
A buffer overflow in the wordwrap() function has been reported.
New packages will be prepared and should be available on our ftp
servers soon.
- wget
A buffer overflow in wget's url_filename function was found.
This buffer overflow can be triggered by long URLs.
New packages are currently being build and will be released
soon.
- IMP
The web front-end of IMP is vulnerable to a SQL injection attack.
New packages are currently being build and will be released
soon.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum
References