SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Your Ad Here
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  OS (UNIX)  >  AIX Vendors:  IBM
IBM AIX Kernel Bugs Let Local Users Execute Arbitrary Code, Access Data, and Deny Service
SecurityTracker Alert ID:  1019606
SecurityTracker URL:  http://securitytracker.com/id?1019606
CVE Reference:  CVE-2008-1593 ,  CVE-2008-1594 ,  CVE-2008-1595 ,  CVE-2008-1596 ,  CVE-2008-1597 ,  CVE-2008-1598   (Links to External Site)
Updated:  Apr 1 2008
Original Entry Date:  Mar 12 2008
Impact:  Denial of service via local system, Execution of arbitrary code via local system, Root access via local system, User access via local system
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 5.2, 5.3, 6.1
Description:  Several vulnerabilities were reported in the IBM AIX kernel. A local user can obtain elevated privileges on the target system. A local user can cause denial of service conditions.

A local 64-bit process that is restarted via the checkpoint and restart feature can gain read and write access to certain portions of kernel memory. A local user can exploit this to execute arbitrary code with kernel-level privileges.

A user on a remote node of a concurrent volume group can reduce the size of a JFS2 filesystem residing on the concurrent volume group can cause a remote node to crash.

When the permission on a directory on a proc filesystem is more restrictive than the permission on an executing file in that directory, directory access controls are not properly enforced.

When a user make modifications via hard links, Trusted Execution does not properly protect files. This vulnerability only affects AIX 6.1.

A local user can invoke some WPAR specific system calls to cause denial of service conditions. This vulnerability only affects AIX 6.1.

A local user with privileges to run ProbeVue can read arbitrary kernel memory locations. This vulnerability only affects AIX 6.1. The following files are affected:

/usr/lib/boot/unix_64
/usr/lib/boot/unix_mp
/usr/lib/boot/unix_up
/usr/lib/drivers/hd_pin
/usr/sbin/lreducelv

IBM discovered these vulnerabilities.

Impact:  A local user can obtain elevated privileges on the target system.

A local user can cause denial of service conditions on the target system.

Solution:  The vendor has issued the following fixes.

For 5.2.0: APAR IZ16992
For 5.3.0: APAR IZ17111 (to be available 3/17/2008)
For 5.3.7: APAR IZ11820 (to be available 3/17/2008)
For 6.1.0: APAR IZ12794

The vendor advisories are available at:

http://www.ibm.com/support/docview.wss?uid=isg1IZ16992
ht tp://www.ibm.com/support/docview.wss?uid=isg1IZ17111
http://www.ibm.com/support/docview.wss?uid=isg1IZ11820
http://www.ibm.com/support/docview.wss?uid=isg1IZ12794

Vendor URL:  www.ibm.com/ (Links to External Site)
Cause:  Access control error, Exception handling error
Underlying OS:  UNIX (AIX)

Message History:   None.


 Source Message Contents

Date:  Tue, 11 Mar 2008 20:28:08 -0500
Subject:  IBM AIX

 
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
IBM SECURITY ADVISORY
 
First Issued: Tue Mar 11 10:01:36 CDT 2008
===============================================================================
                           VULNERABILITY SUMMARY
 
VULNERABILITY:      AIX kernel multiple security vulnerabilities
 
PLATFORMS:          AIX 5.2, 5.3, 6.1
 
SOLUTION:           Apply the fix as described below.
 
THREAT:             An attacker may execute arbitrary code, cause a
                    denial of service, or access privileged data.
 
CVE Number:         n/a
 
Reboot required?    YES
Workarounds?        NO
Protected by FPM?   NO
Protected by SED?   NO
===============================================================================
                           DETAILED INFORMATION
 
I. DESCRIPTION
 
    There are multiple vulnerabilities in the AIX kernel:
 
    a) A 64-bit process that is restarted via the checkpoint and
    restart feature will gain read and write access to certain areas
    of kernel memory, resulting in execution of arbitrary
    code.
    Track with the following APAR numbers: IZ16992, IZ17111, IZ11820,
    IZ12794.  
 
    b) Remote nodes of a concurrent volume group may crash after a
    single node reduces the size of a JFS2 filesystem residing on the
    concurrent volume group, resulting in a denial of service.
    Track with the following APAR numbers: IZ05246, IZ04953, IZ04946.
 
    c) The proc filesystem does not enforce directory access controls
    correctly when the permission on a directory is more restrictive
    than permission on the currently executing file in that directory,
    resulting in information leakage.
    Track with the following APAR numbers: IZ06022, IZ06663, IZ06505.
 
    d) Trusted Execution fails to protect files when the modifications
    are made via hard links.  Affects AIX 6.1 only.
    Track with the following APAR number: IZ13418
 
    e) Some WPAR specific system calls may cause undefined behavior,
    possibly resulting in a denial of service.  Affects AIX 6.1 only.
    Track with the following APAR numbers: IZ13392, IZ13346
 
    f) A user with enough privileges to run ProbeVue can read from any
    kernel memory address, resulting in information leakage.  Affects
    AIX 6.1 only.
    Track with the following APAR number: IZ09545
 
    The following files are vulnerable:
 
    /usr/lib/boot/unix_64
    /usr/lib/boot/unix_mp
    /usr/lib/boot/unix_up
    /usr/lib/drivers/hd_pin
    /usr/sbin/lreducelv
 
    The fixes below include the fixes for all of the above APARs.
 
II. PLATFORM VULNERABILITY ASSESSMENT
 
    To determine if your system is vulnerable, execute the following
    command:
 
    lslpp -L bos.mp64 bos.mp bos.up bos.rte.lvm
 
    The following fileset levels are vulnerable:
 
    AIX Fileset        Lower Level       Upper Level
    ------------------------------------------------
    bos.mp64           5.2.0.85          5.2.0.89
    bos.mp64           5.2.0.95          5.2.0.102
    bos.mp64           5.2.0.105         5.2.0.110
    bos.mp64           5.3.0.50          5.3.0.57
    bos.mp64           5.3.0.60          5.3.0.66
    bos.mp64           5.3.7.0           5.3.7.2
    bos.mp64           6.1.0.0           6.1.0.3
 
    bos.mp             5.2.0.85          5.2.0.89
    bos.mp             5.2.0.95          5.2.0.102
    bos.mp             5.2.0.105         5.2.0.110
    bos.mp             5.3.0.50          5.3.0.57
    bos.mp             5.3.0.60          5.3.0.66
    bos.mp             5.3.7.0           5.3.7.2
 
    bos.rte.lvm        5.2.0.85          5.2.0.88
    bos.rte.lvm        5.2.0.95          5.2.0.99
    bos.rte.lvm        5.2.0.105         5.2.0.106
    bos.rte.lvm        5.3.0.50          5.3.0.55
    bos.rte.lvm        5.3.0.60          5.3.0.62
    bos.rte.lvm        5.3.7.0           5.3.7.0
 
    bos.up             5.2.0.85          5.2.0.89
    bos.up             5.2.0.95          5.2.0.102
    bos.up             5.2.0.105         5.2.0.110
 
III. SOLUTIONS
 
    A. APARS
 
        IBM has assigned the following APARs to this problem:
 
        AIX Level           APAR number        Availability
        ---------------------------------------------------
        5.2.0               IZ16992            Now
        5.3.0               IZ17111            3/17/2008
        5.3.7               IZ11820            3/17/2008
        6.1.0               IZ12794            Now
 
        Subscribe to the APARs here:
 
        http://www.ibm.com/support/docview.wss?uid=isg1IZ16992
        http://www.ibm.com/support/docview.wss?uid=isg1IZ17111
        http://www.ibm.com/support/docview.wss?uid=isg1IZ11820
        http://www.ibm.com/support/docview.wss?uid=isg1IZ12794
 
        By subscribing, you will receive periodic email alerting you
        to the status of the APAR, and a link to download the fix once
        it becomes available.
 
    B. FIXES
 
        Fixes are available.  The fixes can be downloaded via ftp
        from:
 
        ftp://aix.software.ibm.com/aix/efixes/security/kernel_fix.tar
 
        The link above is to a tar file containing this signed
        advisory, fix packages, and PGP signatures for each package.
        The fixes below include prerequisite checking. This will
        enforce the correct mapping between the fixes and AIX
        Technology Levels.
 
        AIX Level          Fix (*.U) and Interim Fix (*.Z)
        -------------------------------------------------------------------
        5.2.0 TL8          IZ16992_8a.080306.epkg.Z
                           IZ16992_8b.080306.epkg.Z
                           IZ16992_8c.080306.epkg.Z
                           IZ16992_8d.080306.epkg.Z
        5.2.0 TL9          IZ16992_9a.080307.epkg.Z
                           IZ16992_9b.080306.epkg.Z
                           IZ16992_9c.080306.epkg.Z
                           IZ16992_9d.080306.epkg.Z
        5.2.0 TL10         bos.mp.5.2.0.111.U
                           bos.mp64.5.2.0.111.U
                           bos.up.5.2.0.111.U
                           bos.rte.lvm.5.2.0.107.U
        5.3.0 TL5          IZ17111_5a.080306.epkg.Z
                           IZ17111_5b.080306.epkg.Z
                           IZ17111_5c.080306.epkg.Z
                           IZ17111_5d.080306.epkg.Z
        5.3.0 TL6          IZ17111_6a.080306.epkg.Z
                           IZ17111_6b.080306.epkg.Z
                           bos.rte.lvm.5.3.0.64.U
        5.3.7              IZ11820_7a.080306.epkg.Z
                           IZ11820_7b.080306.epkg.Z
                           bos.rte.lvm.5.3.7.1.U
        6.1.0              bos.mp64.6.1.0.4.U
 
        To extract the fixes from the tar file:
 
        tar xvf kernel_fix.tar
        cd kernel_fix
 
        Verify you have retrieved the fixes intact:
 
        The checksums below were generated using the "sum", "cksum",
        "csum -h MD5" (md5sum), and "csum -h SHA1" (sha1sum) commands
        and are as follows:
 
        sum         filename
        ------------------------------------
        41878  5620 bos.mp.5.2.0.111.U
        12951  5975 bos.mp64.5.2.0.111.U
        51678 27683 bos.mp64.6.1.0.4.U
        48971  1989 bos.rte.lvm.5.2.0.107.U
        05910  2606 bos.rte.lvm.5.3.0.64.U
        65343  2788 bos.rte.lvm.5.3.7.1.U
        22827  5021 bos.up.5.2.0.111.U
        35484  5087 IZ11820_7a.080306.epkg.Z
        45602  4825 IZ11820_7b.080306.epkg.Z
        16407   113 IZ16992_8a.080306.epkg.Z
        11714  3708 IZ16992_8b.080306.epkg.Z
        50041  3588 IZ16992_8c.080306.epkg.Z
        46067  3349 IZ16992_8d.080306.epkg.Z
        49122   113 IZ16992_9a.080307.epkg.Z
        18653  3743 IZ16992_9b.080306.epkg.Z
        62615  3623 IZ16992_9c.080306.epkg.Z
        39339  3401 IZ16992_9d.080306.epkg.Z
        00170   118 IZ17111_5a.080306.epkg.Z
        08086    10 IZ17111_5b.080306.epkg.Z
        35123  4995 IZ17111_5c.080306.epkg.Z
        19037  4746 IZ17111_5d.080306.epkg.Z
        14321  5050 IZ17111_6a.080306.epkg.Z
        44698  4804 IZ17111_6b.080306.epkg.Z
 
        cksum              filename
        -------------------------------------------
        1769871756 5754880 bos.mp.5.2.0.111.U
        854968964 6118400 bos.mp64.5.2.0.111.U
        1292352585 28347392 bos.mp64.6.1.0.4.U
        3765659627 2036736 bos.rte.lvm.5.2.0.107.U
        4292727698 2668544 bos.rte.lvm.5.3.0.64.U
        656759935 2854912 bos.rte.lvm.5.3.7.1.U
        760439356 5141504 bos.up.5.2.0.111.U
        2382658090 5208781 IZ11820_7a.080306.epkg.Z
        3885633244 4940563 IZ11820_7b.080306.epkg.Z
        2070295023 115495 IZ16992_8a.080306.epkg.Z
        735615564 3796809 IZ16992_8b.080306.epkg.Z
        611408700 3673977 IZ16992_8c.080306.epkg.Z
        2166905248 3428899 IZ16992_8d.080306.epkg.Z
        2170429470 115691 IZ16992_9a.080307.epkg.Z
        1014656148 3832647 IZ16992_9b.080306.epkg.Z
        3324704410 3709339 IZ16992_9c.080306.epkg.Z
        1795641163 3482555 IZ16992_9d.080306.epkg.Z
        3400540784 120191 IZ17111_5a.080306.epkg.Z
        2984586224 9775 IZ17111_5b.080306.epkg.Z
        3764592368 5114773 IZ17111_5c.080306.epkg.Z
        2456126235 4859115 IZ17111_5d.080306.epkg.Z
        222011986 5170787 IZ17111_6a.080306.epkg.Z
        2186942398 4919125 IZ17111_6b.080306.epkg.Z
 
        csum -h MD5 (md5sum)              filename
        ----------------------------------------------------------
        5186489f79b0afc131d411225a346999  bos.mp.5.2.0.111.U
        5352a3bd27bae5dca4e4e37ab99fbaae  bos.mp64.5.2.0.111.U
        71697c6d95aec28488744015419dc399  bos.mp64.6.1.0.4.U
        0c73aa8f0211c400455feaa6fb8a95c4  bos.rte.lvm.5.2.0.107.U
        2f8ad145066390e12e2252446a183944  bos.rte.lvm.5.3.0.64.U
        5924783e27116fc537e8f61b2275dddb  bos.rte.lvm.5.3.7.1.U
        584b6e68e357061347ebba1cb02d1e44  bos.up.5.2.0.111.U
        3bdf0c6b42d51f464565d4b979065393  IZ11820_7a.080306.epkg.Z
        26fdf12c819265bb0cdce0706973b9bd  IZ11820_7b.080306.epkg.Z
        dd7dbdd27a20055252321c56a6a6350b  IZ16992_8a.080306.epkg.Z
        3c62749f4652ae0106d647244e21cfc1  IZ16992_8b.080306.epkg.Z
        a08adda9df1864ef6aba017e3c194797  IZ16992_8c.080306.epkg.Z
        f7ae9572cb6091232b916ec695bac6ac  IZ16992_8d.080306.epkg.Z
        27fd38800e29ad4b7ddc97bda9fedcc2  IZ16992_9a.080307.epkg.Z
        1944d6c2e00de4c755e5f0c08546db74  IZ16992_9b.080306.epkg.Z
        80ef4f2238bd6ee647ca89563f6d74da  IZ16992_9c.080306.epkg.Z
        7e28e491d2d2ba3e300603d10f511b8e  IZ16992_9d.080306.epkg.Z
        a5117f2b30ecf9b6a62c30cb4b5a9e7f  IZ17111_5a.080306.epkg.Z
        0dc97a5bcb07582db1c51ef5c714f245  IZ17111_5b.080306.epkg.Z
        f66821b93102a8521b7f4294549f1aa7  IZ17111_5c.080306.epkg.Z
        83a0b7b1002a28a8896be6209c9bda78  IZ17111_5d.080306.epkg.Z
        0209225b08a8ea140edcc49779856798  IZ17111_6a.080306.epkg.Z
        399a7cacd446a17d99dc07b2556a5017  IZ17111_6b.080306.epkg.Z
 
        csum -h SHA1 (sha1sum)                    filename
        ------------------------------------------------------------------
        06fef79ed1644e0781b729abc7ecb5f81f843e0c  bos.mp.5.2.0.111.U
        561fc6f66a74e44c02eaecf2d55930dc29027126  bos.mp64.5.2.0.111.U
        13904b26d77f4c38cc48dc4c44bfa45d39eaa2a0  bos.mp64.6.1.0.4.U
        4589a5bca998f437aac5c3bc2c222eaa51490dab  bos.rte.lvm.5.2.0.107.U
        1b6544f470ddb19fa84ca03bbdc6ff55216f8df7  bos.rte.lvm.5.3.0.64.U
        99bb3c53d7fca9cd0f9ae96e31c4d48ca4fb8bbe  bos.rte.lvm.5.3.7.1.U
        ed3724acab75a4e751c99b2f9a034196bef2dd27  bos.up.5.2.0.111.U
        f4dc336263da0fc500f0d7ab3de0e96e21baadf7  IZ11820_7a.080306.epkg.Z
        a893913e8ce82acc3490dd007aaa04c09c8ec5a0  IZ11820_7b.080306.epkg.Z
        1c766f2af50743f87673cef6a4e33ce8487c7e5c  IZ16992_8a.080306.epkg.Z
        85515b38a0ef970ebaea64a211e2eeb19e23d9d9  IZ16992_8b.080306.epkg.Z
        0d152cd131b0259fa1a7295ba33de25f2fe70bd0  IZ16992_8c.080306.epkg.Z
        99fc78dfc6cfbb522853b35173c6328e455be2d1  IZ16992_8d.080306.epkg.Z
        09f81efded8e5c6c96975e60e04b728c53656161  IZ16992_9a.080307.epkg.Z
        b22d6ba6e1ab6912ae3520a96ba4fa9188352671  IZ16992_9b.080306.epkg.Z
        f0d2a2466027ee312eedd02745c7b7a4f38a30fa  IZ16992_9c.080306.epkg.Z
        3aeb8ca3d0e55990f7b9d7f345a0729b641696b6  IZ16992_9d.080306.epkg.Z
        5db5eea7dcdf6d9eef6766d006d824cc5c7b6620  IZ17111_5a.080306.epkg.Z
        4cc96eff6aeaa48c5417a287c1ce84a3fb2a3a2d  IZ17111_5b.080306.epkg.Z
        b3a966360781db061dcfb268d8370e5b8b39d4e4  IZ17111_5c.080306.epkg.Z
        7e37864a3c19ef3a1c559d7ca03f9860734cc189  IZ17111_5d.080306.epkg.Z
        33ba9211e4206cf3c83945d823aa376c31863fe1  IZ17111_6a.080306.epkg.Z
        8acf7122a26620a6550b628474c07cba1bc07c0c  IZ17111_6b.080306.epkg.Z
 
        To verify the sums, use the text of this advisory as input to
        csum, md5sum, or sha1sum. For example:
 
        csum -h SHA1 -i Advisory.asc
        md5sum -c Advisory.asc
        sha1sum -c Advisory.asc
 
        These sums should match exactly. The PGP signatures in the tar
        file and on this advisory can also be used to verify the
        integrity of the fixes.  If the sums or signatures cannot be
        confirmed, contact IBM AIX Security at
        security-alert@austin.ibm.com and describe the discrepancy.
 
     C. FIX AND INTERIM FIX INSTALLATION
 
        IMPORTANT: If possible, it is recommended that a mksysb backup
        of the system be created.  Verify it is both bootable and
        readable before proceeding.
 
        To preview a fix installation:
 
        installp -a -d fix_name -p all  # where fix_name is the name of the
                                        # fix package being previewed.
        To install a fix package:
 
        installp -a -d fix_name -X all  # where fix_name is the name of the  
                                        # fix package being installed.
 
        Interim fixes have had limited functional and regression
        testing but not the full regression testing that takes place
        for Service Packs; thus, IBM does not warrant the fully
        correct functionality of an interim fix.
 
        Interim fix management documentation can be found at:
 
        http://www14.software.ibm.com/webapp/set2/sas/f/aix.efixmgmt/home.html
 
        To preview an interim fix installation:
 
        emgr -e ipkg_name -p         # where ipkg_name is the name of the  
                                     # interim fix package being previewed.
 
        To install an interim fix package:
 
        emgr -e ipkg_name -X         # where ipkg_name is the name of the  
                                     # interim fix package being installed.
 
IV. WORKAROUNDS
 
    There are no workarounds.
 
V. OBTAINING FIXES
 
    AIX security fixes can be downloaded from:
 
        ftp://aix.software.ibm.com/aix/efixes/security
 
    AIX fixes can be downloaded from:
 
        http://www.ibm.com/eserver/support/fixes/fixcentral/main/pseries/aix
 
    NOTE: Affected customers are urged to upgrade to the latest
    applicable Technology Level and Service Pack.
 
VI. CONTACT INFORMATION
 
    If you would like to receive AIX Security Advisories via email,
    please visit:
 
        http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd
 
    Comments regarding the content of this announcement can be
    directed to:
 
        security-alert@austin.ibm.com
 
    To request the PGP public key that can be used to communicate
    securely with the AIX Security Team you can either:
 
        A. Send an email with "get key" in the subject line to:
 
            security-alert@austin.ibm.com
 
        B. Download the key from a PGP Public Key Server. The key ID is:
 
            0xA6A36CCC
 
    Please contact your local IBM AIX support center for any
    assistance.
 
    eServer is a trademark of International Business Machines
    Corporation.  IBM, AIX and pSeries are registered trademarks of
    International Business Machines Corporation.  All other trademarks
    are property of their respective holders.
 
VII. ACKNOWLEDGMENTS
 
    IBM discovered and fixed this vulnerability as part of its
    commitment to secure the AIX operating system.
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (AIX)
 
iD8DBQFH1r968lficKajbMwRAgHxAJ9AZTBtlbZJS2AG8w5i2aLhIBSJbgCgrV3F
IsM+45ajM3+9bmSegMamXXA=
=GemZ
-----END PGP SIGNATURE-----
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2007, SecurityGlobal.net LLC