"

Recent SCO/Linux News


Index
Recent SCO Security Info
Recent SCO TA's
There is a LOT more here: try Searching this site


From: security@caldera.com
Subject: Security Update: [CSSA-2001-SCO.39] Open UNIX, UnixWare 7: timed does not enforce nulls
Date: Tue, 11 Dec 2001 01:42:10 GMT


Hate these ads?




--3V7upXqbjpZ4EhLz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable



To: bugtraq@securityfocus.com announce@lists.caldera.com scoannmod@xenitec.=
on.ca








___________________________________________________________________________



            Caldera International, Inc. Security Advisory



Subject:                Open UNIX, UnixWare 7: timed does not enforce nulls
Advisory number:        CSSA-2001-SCO.39
Issue date:             2001 December 10
Cross reference:
___________________________________________________________________________




1. Problem Description
=09
        The timed program does not enforce null-termination of strings
        in certain situations. It is possible that this could be used
        by a malicious user to perform a remote denial-of-service
        attack.


ad




2. Vulnerable Versions



        Operating System        Version         Affected Files
        ------------------------------------------------------------------
        UnixWare 7              All             /usr/sbin/in.timed
        Open UNIX               8.0.0           /usr/sbin/in.timed




3. Workaround



        If the in.timed service is not needed, it may be disabled.




4. UnixWare 7, Open UNIX 8



  4.1 Location of Fixed Binaries



        ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.39/




  4.2 Verification



        md5 checksums:
=09
        87c68b618f4317dd92460aaa49e6a522        erg711890.Z




        md5 is available for download from



                ftp://stage.caldera.com/pub/security/tools/




  4.3 Installing Fixed Binaries



        Upgrade the affected binaries with the following commands:



        # uncompress /tmp/erg711890.Z
        # pkgadd -d /tmp/erg711890




5. References



        http://xforce.iss.net/static/6228.php
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2001-0388



        This and other advisories are located at
                http://stage.caldera.com/support/security



        This advisory addresses Caldera Security internal incidents
        sr855196, fz519311, erg711890.




6. Disclaimer



        Caldera International, Inc. is not responsible for the misuse
        of any of the information we provide on our website and/or
        through our security advisories. Our advisories are a service
        to our customers intended to promote secure installation and
        use of Caldera International products.




7. Acknowledgements



        This vulnerability was discovered and researched by David A.
        Holland <dholland@www.linux.org.uk>.
    =20



        =20
___________________________________________________________________________



--3V7upXqbjpZ4EhLz
Content-Type: application/pgp-signature
Content-Disposition: inline



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (SCO_SV)
Comment: For info see http://www.gnupg.org



iEYEARECAAYFAjwVZHIACgkQaqoBO7ipriHEGACdGTuhPlva0PpRiIE6neJUhEsw
acoAn2K5PyT45yeOM8Zt8VseaSIzJX6h
=CY9g
-----END PGP SIGNATURE-----



--3V7upXqbjpZ4EhLz--



Index






Enter your email address for automatic notification of new posts here
(be sure to whitelist 'feedburner.com' if you use spam filtering)

Or use any RSS reader

Delivered by FeedBurner

cartoon
Need eyes on the ground at your customer's site?
Installation and light training Boston and New England
Reliable and experienced, punctual and professional.


Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.

Publishing your articles here

More:




Unix/Linux Consultants

Your ad here - $48.00 yearly!

http://thatitguy.com Business networking servers, Linux and Unix experts. In business since 1997! Windows and Exchange to Samba and Scalix migration experts.


http://www.vss3.com SCO/Caldera OpenServer, Unixware & Linux. Tarantella & Non-stop Clustering


http://www.cleverminds.net Need expert advice? Want a second opinion? CleverMinds is a one-stop-shop for a wide range of technology solutions. We support Unix, Linux, SCO as well as CMS, ecom, blogs, podcasts, search engines consulting and more. Contact us at web2.0@cleverminds.net 0r (617) 894-1282



Twitter
  • Nov 21 07:40
    @loudmouthman: well, a digital signature could prove it hadn't been altered. Text is no more insecure than anything else in that sense.
  • Nov 21 07:38
    Uggh. Lost $11.50 at poker last night by playing thoughtlessly and carelessly.




card_image








Change Congress


Related Posts