(Additional Exploit Information) Re: The Expect Mkpasswd Utility Generates a Relatively Small Number of Passwords, Making Brute Force Password Guessing Attempts Easier
|
|
SecurityTracker Alert ID: 1001307 |
|
SecurityTracker URL: http://securitytracker.com/id/1001307
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Apr 13 2001
|
Impact:
User access via network, error
|
|
|
Description:
A vulnerability was reported in the "mkpasswd" password generation utility that is included as part of an Expect package. The utility may generate vulnerable password information.
The utility reportedly generates a relatively small number of passwords (2^15 passwords for the default password length). This may be due to the utility's password restriction rules that attempt to generate "good" passwords.
A user adds that, due to a fault in Expect (the interpreter that runs the mkpasswd script), a local user can cause arbitrary commands to be executed with different user privileges. For sketchy details, see the source message.
|
Impact:
A remote user may be able to determine passwords via brute force cracking in a short period of time if those passwords were generated by the mkpasswd utility.
It may also be possible for a local user to cause arbitrary commands to be executed with different user privileges.
|
Solution:
No solution was available at the time of this entry.
|
Cause:
Authentication error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 13 Apr 2001 05:29:42 -0000
Subject: mkpasswd: acutally its worse than just not many passwords
|
due to a fault in expect (the interpreter that runs the mkpasswd script) it is trivially easy to cause arbitrary commands to be executed
by someone else.
(under RH7.0 anyway)
the search path for libs for it includes /var/tmp/
check out
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224
for details, and
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187
for an exploit. (Although the 1st is marked as a duplicate of the 2nd, as one of the notes mentions they cover completely different
areas. Also note that the severity ratings of both of them are blank? Fjeer)
--zen-parse
*********************
**more to come soon**
*********************
Fix is kinda available.
Sign up for your FREE E-MAIL account @ Dynamitemail:
http://www.dynamitemail.com
|
|