SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   OS (UNIX)  >   AIX Vendors:   IBM
IBM AIX LDAP Bug Lets Remote Users Bypass Authentication
SecurityTracker Alert ID:  1025273
SecurityTracker URL:  http://securitytracker.com/id/1025273
CVE Reference:   CVE-2011-1561   (Links to External Site)
Updated:  Apr 7 2011
Original Entry Date:  Mar 31 2011
Impact:   User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 6.1.6.4
Description:   A vulnerability was reported in IBM AIX. A remote user can login with the wrong password.

On systems that have installed bos.rte.security 6.1.6.4 fileset, a remote user can login with an incorrect password.

When a LDAP user account authtype is set to ldap_auth in the '/etc/security/ldap/ldap.cfg' file, the account is affected.

When a non-LDAP user account has their SYSTEM attribute in the '/etc/security/user' file set to SYSTEM = "LDAP or compat" or when the default stanza is set to SYSTEM = "LDAP or compat" and local users do not have their SYSTEM attribute set in their own stanza, the account is affected.

Impact:   A remote user can login with the wrong password.
Solution:   The vendor has issued a fix (APAR IZ97416), available at:

http://aix.software.ibm.com/aix/efixes/security/ldapauth_fix.tar
ftp://aix.software.ibm.com/aix/efixes/security/ldapauth_fix.tar

The vendor's advisory is available at:

http://aix.software.ibm.com/aix/efixes/security/ldapauth_advisory.asc

Vendor URL:  aix.software.ibm.com/aix/efixes/security/ldapauth_advisory.asc (Links to External Site)
Cause:   Authentication error
Underlying OS:  

Message History:   None.


 Source Message Contents

Date:  Thu, 31 Mar 2011 18:23:40 +0000
Subject:  IBM AIX


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

IBM SECURITY ADVISORY

First Issued: Thu Mar 31 10:05:05 CDT 2011

The most recent version of this document is available here:

http://aix.software.ibm.com/aix/efixes/security/ldapauth_advisory.asc
or
ftp://aix.software.ibm.com/aix/efixes/security/ldapauth_advisory.asc
===============================================================================
VULNERABILITY SUMMARY

VULNERABILITY: LDAP login vulnerability applies to AIX 6100-06

PLATFORMS: AIX 6.1

SOLUTION: Apply the fix as described below

THREAT: An attacker may login with an incorrect password

CERT VU Number: n/a
CVE Number: n/a

Reboot required? NO
Workarounds? NO
Protected by FPM? NO (high, medium, or low)
Protected by SED? NO
===============================================================================
DETAILED INFORMATION

I. OVERVIEW

After installing bos.rte.security 6.1.6.4 fileset, an LDAP user will be
able to log in with an incorrect password. This occurs only when authtype
is set to ldap_auth in the /etc/security/ldap/ldap.cfg file. Non-LDAP
users can also log in with incorrect passwords if the local users have
their SYSTEM attribute in the /etc/security/user file is set to
SYSTEM = "LDAP or compat", or the default stanza is set to SYSTEM =
"LDAP or compat" and local users do not have SYSTEM set in their own
stanza. If local users don't have LDAP in their SYSTEM attribute, then
they will not be affected.

II. PLATFORM VULNERABILITY ASSESSMENT

To determine if your system is vulnerable, execute the following
command:

lslpp -L bos.rte.security

The following fileset levels are vulnerable:

AIX Fileset Lower Level Upper Level
---------------------------------------------------
bos.rte.security 6.1.6.4 6.1.6.4

III. SOLUTIONS

A. APARS

IBM has assigned the following APARs to this problem:

AIX Level APAR number Availability
----------------------------------------------------
6.1.6 IZ97416 TBD

Subscribe to the APARs here:

http://www.ibm.com/support/docview.wss?uid=isg1IZ97416

By subscribing, you will receive periodic email alerting you
to the status of the APAR, and a link to download the fix once
it becomes available.

B. FIXES

Fixes are now available. The fixes can be downloaded from:

http://aix.software.ibm.com/aix/efixes/security/ldapauth_fix.tar
ftp://aix.software.ibm.com/aix/efixes/security/ldapauth_fix.tar

The links above are to a tar file containing this signed
advisory, fix packages, and PGP signatures for each package.
The fixes below include prerequisite checking. This will
enforce the correct mapping between the fixes and AIX
Technology Levels.

AIX Level Fix
----------------------------------------------------
6.1.6 IZ97416s04.110329.epkg.Z

To extract the fixes from the tar file:

tar xvf ldapauth_fix.tar
cd ldapauth_fix

Verify you have retrieved the fixes intact:

The checksums below were generated using the "sum", "cksum",
"csum -h MD5" (md5sum), and "csum -h SHA1" (sha1sum) commands
and are as follows:

sum filename
------------------------------------
35429 100 IZ97416s04.110329.epkg.Z

cksum filename
-------------------------------------------
3033455980 102107 IZ97416s04.110329.epkg.Z

csum -h MD5 (md5sum) filename
----------------------------------------------------------
19762b32584c2ed966c0392c34318159 IZ97416s04.110329.epkg.Z


csum -h SHA1 (sha1sum) filename
------------------------------------------------------------------
1340021a3b4d47bdeafb96165ecc1cbad9a35ddd IZ97416s04.110329.epkg.Z

To verify the sums, use the text of this advisory as input to
csum, md5sum, or sha1sum. For example:

csum -h SHA1 -i Advisory.asc
md5sum -c Advisory.asc
sha1sum -c Advisory.asc

These sums should match exactly. The PGP signatures in the tar
file and on this advisory can also be used to verify the
integrity of the fixes. If the sums or signatures cannot be
confirmed, contact IBM AIX Security and describe the
discrepancy at the following address:

security-alert@austin.ibm.com

C. INTERIM FIX INSTALLATION

IMPORTANT: If possible, it is recommended that a mksysb backup
of the system be created. Verify it is both bootable and
readable before proceeding.

Interim fixes have had limited functional and regression
testing but not the full regression testing that takes place
for Service Packs; thus, IBM does not warrant the fully
correct functionality of an interim fix.

Interim fix management documentation can be found at:

http://www14.software.ibm.com/webapp/set2/sas/f/aix.efixmgmt/home.html

To preview an interim fix installation:

emgr -e ipkg_name -p # where ipkg_name is the name of the
# interim fix package being previewed.

To install an interim fix package:

emgr -e ipkg_name -X # where ipkg_name is the name of the
# interim fix package being installed.


IV. WORKAROUNDS

None.

V. OBTAINING FIXES

AIX security fixes can be downloaded from:

http://aix.software.ibm.com/aix/efixes/security
or
ftp://aix.software.ibm.com/aix/efixes/security

AIX fixes can be downloaded from:

http://www.ibm.com/eserver/support/fixes/fixcentral/main/pseries/aix

NOTE: Affected customers are urged to upgrade to the latest
applicable Technology Level and Service Pack.

VI. CONTACT INFORMATION

If you would like to receive AIX Security Advisories via email,
please visit:

http://www.ibm.com/systems/support

and click on the "My notifications" link.

To view previously issued advisories, please visit:

http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd

Comments regarding the content of this announcement can be
directed to:

security-alert@austin.ibm.com

To obtain the PGP public key that can be used to communicate
securely with the AIX Security Team you can either:

A. Download the key from our web page:

http://www.ibm.com/systems/resources/systems_p_os_aix_security_pgpkey.txt

B. Download the key from a PGP Public Key Server. The key ID is:

0x28BFAA12

Please contact your local IBM AIX support center for any
assistance.

eServer is a trademark of International Business Machines
Corporation. IBM, AIX and pSeries are registered trademarks of
International Business Machines Corporation. All other trademarks
are property of their respective holders.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (AIX)

iD8DBQFNlJlw4fmd+Ci/qhIRAsC9AJ9bwhqLk+gX8/xaTm4v6WmbAgrubgCfXoXL
owt5SiIaUaN/HaFa2U7r/M0=
=92EM
-----END PGP SIGNATURE-----

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC