SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Device (Embedded Server/Appliance)  >   IBM Hardware Management Console Vendors:   IBM
(IBM Issues Fix for AIX) IBM Hardware Management Console Pegasus CIM Bug Lets Remote Users Deny Service
SecurityTracker Alert ID:  1019472
SecurityTracker URL:  http://securitytracker.com/id/1019472
CVE Reference:   CVE-2008-0495   (Links to External Site)
Date:  Feb 21 2008
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   A vulnerability was reported in IBM Hardware Management Console in the Pegasus CIM server. A remote user can cause denial of service conditions.

The CIM service daemon is affected. No further details were provided.

Impact:   A remote user can cause denial of service conditions.
Solution:   IBM has issued a fix for AIX.

Images for AIX 5.3 and AIX 6.1 will be available on April 2008.

Interim Fixes are available via HTTP or Download Director from the IBM Director Web Download Site at:

https://www14.software.ibm.com/webapp/iwm/web/preLogin.do?source=dmp

Fixes for Pegasus 2.6.1 on AIX:

AIX 5.2: Efix_644427.080123_AIX5.2.tar.gz
AIX 5.3: Efix_644427.080123_AIX5.3_6.1.tar.gz
AIX 6.1: Efix_644427.080123_AIX5.3_6.1.tar.gz

Fixes for Pegasus 2.5.1 on AIX:

AIX (all versions): Efix_641416.080123_AIX.tar.gz

Interim Fixes are also available via FTP from the AIX Software Download Site:

ftp://aix.software.ibm.com/aix/efixes/security/pegasus_ifix.tar

Pegasus 2.5.1, All Efix_641416.080123_AIX.tar.gz
Pegasus 2.6.1, 5.2 Efix_644427.080123_AIX5.2.tar.gz
Pegasus 2.6.1, 5.3, 6.1 Efix_644427.080123_AIX5.3_6.1.tar.gz

Vendor URL:  www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html#MH01081 (Links to External Site)
Cause:   Not specified
Underlying OS:   UNIX (AIX)

Message History:   This archive entry is a follow-up to the message listed below.
Jan 29 2008 IBM Hardware Management Console Pegasus CIM Bug Lets Remote Users Deny Service



 Source Message Contents

Date:  Thu, 21 Feb 2008 16:34:28 -0500
Subject:  IBM Pegasus CIM Server for Director on AIX vulnerabilities.



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

IBM SECURITY ADVISORY

First Issued: Thu Feb 21 10:43:47 CST 2008
===============================================================================
                           VULNERABILITY SUMMARY

VULNERABILITY:   IBM Pegasus CIM Server for Director on AIX vulnerabilities.

PLATFORMS:       AIX 5.2, 5.3, 6.1

SOLUTION:        Apply the fix or workaround as described below.

THREAT:          A remote attacker may run arbitrary code with root privileges,
                 and/or cause a Denial of Service (DoS) attack.

CERT VU Number:  n/a
CVE Number:      CVE-2008-0003, CVE-2008-0495
===============================================================================
                           DETAILED INFORMATION

I. OVERVIEW

    IBM Pegasus CIM Server for Director provides common information model
    (CIM) object management. This is a framework supporting Web-Based 
    Enterprise Management (WBEM) services. WBEM is a platform and resource 
    independent standard from the Distributed Management Task Force (DMTF).
    WBEM defines a CIM, and communication protocol for resource monitoring 
    and control. 

    Two vulnerabilities have been addressed in the IBM Pegasus CIM Server
    for Director. The first is a stack buffer overflow flaw found in the PAM
    authentication code in the CIM management server. The second is a Denial
    of Service (DoS) vulnerability against the CIM service daemon itself.

II. DESCRIPTION

    A stack-based buffer overflow vulnerability exists in the IBM Pegasus CIM 
    Server for Director in which an unauthenticated remote user could trigger 
    this flaw and potentially execute arbitrary code with root privileges
    (CVE-2008-0003). In addition a denial-of-service (DoS) issue exists in
    the IBM Pegasus CIM Server for Director.

III. IMPACT

    The successful exploitation of these vulnerabilities allows a
    non-privileged remote user to execute code with root privileges
    and/or cause a denial of service against the CIM server.

IV. PLATFORM VULNERABILITY ASSESSMENT

    To determine if your system is vulnerable, run the following commands:

    lslpp -L sysmgt.pegasus.cimserver.rte

    The following fileset levels are vulnerable for all supported versions
    of AIX:

    AIX Fileset                   Fileset Levels
    ----------------------------------------------------------------
    sysmgt.pegasus.cimserver.rte  2.5.1.20
                                  2.5.1.21
                                  2.5.1.30

    sysmgt.pegasus.cimserver.rte  2.6.1.0
                                  2.6.1.1

V. SOLUTIONS

    A. Installable images including these fixes for AIX 5.3 and AIX 6.1 will 
       be available for IBM Pegasus CIM Server on the IBM Director Download 
       website approximately in April 2008.  These images will install 
       fileset 'sysmgt.cimserver.pegasus.rte' level 2.6.1.20.

    B. INTERIM FIXES

        Interim Fixes are available.  The fixes can be downloaded in two ways:

        1. Via HTTP or Download Director from the IBM Director Web Download 
           Site:

           https://www14.software.ibm.com/webapp/iwm/web/preLogin.do?source=dmp

           NOTE: Once logged in to the site, the fixes can be located
           using the following steps:

           Fixes for Pegasus 2.6.1 on AIX:
            - Select IBM Director for AIX and accept the license.
            - Find the fixes in the IBM Pegasus CIM Server for Director on 
              AIX section:

                  AIX 5.2: Efix_644427.080123_AIX5.2.tar.gz
                  AIX 5.3: Efix_644427.080123_AIX5.3_6.1.tar.gz
                  AIX 6.1: Efix_644427.080123_AIX5.3_6.1.tar.gz

           Fixes for Pegasus 2.5.1 on AIX:
            - Select IBM Director-Archives.
            - Find the fixes in the IBM Director for AIX and Linux on 
              POWER section:

                  AIX (all versions): Efix_641416.080123_AIX.tar.gz

           Install instructions are included in the file:

               CIM_Pegasus_Providers_AIX.README.html 

        2. Via FTP from the AIX Software Download Site:

           ftp://aix.software.ibm.com/aix/efixes/security/pegasus_ifix.tar

        The link above is to a tar file containing this signed
        advisory, interim fix packages, and PGP signatures for each
        package.  The interim fixes below include prerequisite
        checking. This will enforce the correct mapping between the
        fixes and AIX Technology Levels.

        Version        AIX Release  Interim fix
        -----------------------------------------------------------------
        Pegasus 2.5.1  All          Efix_641416.080123_AIX.tar.gz
        Pegasus 2.6.1  5.2          Efix_644427.080123_AIX5.2.tar.gz
        Pegasus 2.6.1  5.3, 6.1     Efix_644427.080123_AIX5.3_6.1.tar.gz

        To extract the fixes from the tar file:

        tar xvf pegasus_ifix.tar
        cd pegasus_ifix

        IMPORTANT: If possible, it is recommended that a mksysb backup
        of the system be created.  Verify it is both bootable and
        readable before proceeding.

        These interim fixes have not been fully regression tested;
        thus, IBM does not warrant the fully correct functionality of
        the interim fix.
        
        Verify you have retrieved the fixes intact:

        The checksums below were generated using the "sum", "cksum",
        "csum -h MD5" (md5sum), and "csum -h SHA1" (sha1sum) commands
        and are as follows:

sum         filename
- ------------------------------------
53770  3610 Efix_641416.080123_AIX.tar.gz
47815   169 Efix_644427.080123_AIX5.2.tar.gz
33258   169 Efix_644427.080123_AIX5.3_6.1.tar.gz

cksum              filename
- ------------------------------------------
4271833127 3695746 Efix_641416.080123_AIX.tar.gz
1284858963  172713 Efix_644427.080123_AIX5.2.tar.gz
2454864014  172998 Efix_644427.080123_AIX5.3_6.1.tar.gz

csum -h MD5 (md5sum)              filename
- ----------------------------------------------------------
8d71ff3be9f60722d4f158bb0e5c2558  Efix_641416.080123_AIX.tar.gz
3aadb16572166fd190a6fb63ddbf85da  Efix_644427.080123_AIX5.2.tar.gz
04c876224b116e2c23778ca941669e29  Efix_644427.080123_AIX5.3_6.1.tar.gz

csum -h SHA1 (sha1sum)                    filename
- ------------------------------------------------------------------
1b9edb622a24c06cf8155fd836235a4a337fbfaf  Efix_641416.080123_AIX.tar.gz
3c69ca8f6213312c4179e6e026cd3ebe8469b7ed  Efix_644427.080123_AIX5.2.tar.gz
022a84b9bd0710bce3dc295b96ddeb0214355563  Efix_644427.080123_AIX5.3_6.1.tar.gz

        To verify the sums, use the text of this advisory as input to
        csum, md5sum, or sha1sum. For example:

        csum -h SHA1 -i Advisory.asc
        md5sum -c Advisory.asc
        sha1sum -c Advisory.asc

        These sums should match exactly. The PGP signatures in the tar
        file and on this advisory can also be used to verify the
        integrity of the fixes.  If the sums or signatures cannot be
        confirmed, contact IBM AIX Security at
        security-alert@austin.ibm.com and describe the discrepancy.

    C. INTERIM FIX INSTALLATION

        Please refer to the installation instructions in the following
        files:

        Efix_641416_readme.html
        Efix_644427_readme.html

VI. WORKAROUNDS

    There are no workarounds for these vulnerabilities other than 
    uninstalling the affected software.

VII. OBTAINING FIXES

    Security related Interim Fixes can be downloaded from:

        ftp://aix.software.ibm.com/aix/efixes/security

VIII. CONTACT INFORMATION

    If you would like to receive AIX Security Advisories via email,
    please visit:

        http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd
 
    Comments regarding the content of this announcement can be
    directed to:

        security-alert@austin.ibm.com

    To request the PGP public key that can be used to communicate
    securely with the AIX Security Team you can either:

        A. Send an email with "get key" in the subject line to:

            security-alert@austin.ibm.com

        B. Download the key from a PGP Public Key Server. The key ID is:

            0xA6A36CCC

    Please contact your local IBM AIX support center for any
    assistance.

    eServer is a trademark of International Business Machines
    Corporation.  IBM, AIX and pSeries are registered trademarks of
    International Business Machines Corporation.  All other trademarks
    are property of their respective holders.

IX. ACKNOWLEDGMENTS

    RedHat security auditors and the IBM Hardware Management Console
    for discovering/reporting these vulnerabilities.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (AIX)

iD8DBQFHvbHe8lficKajbMwRArWuAKCZTY4Cx7ttVtvREp1ZkW/bgZPEFACaA8bv
LPxfbPEyDgoquvEG+E/NNbg=
=4y99
-----END PGP SIGNATURE-----
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC