OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: AIX Service Mail Server (aixservaustin.ibm.com)
Date: Sat Jun 29 2002 - 15:28:01 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    This file contains summary information on AIX security alerts published
    by the Computer Emergency Response Team (CERT), and the IBM Emergency
    Response Team (ERS). The full text of these alerts can be obtained from
    this mail server by requesting the 'CERT' and 'ERS' files. This
    information (and more) is available from CERT and ERS directly on the
    world-wide web at the following URLs:

      CERT: http://www.cert.org/

       ERS: http://www.ers.ibm.com/

    In order to keep the size of this file reasonable, it contains only
    advisories for the current year.. You can obtain a list of previous
    advisories either from the above URLs, or by requesting one of the
    "Security_YYYY" documents from this mail server.

    The fixes mentioned in this document, when available, can be obtained
    from Electronic Fix Distribution at the following URL:

      http://techsupport.services.ibm.com/server/fixes

    The 'Security_APARs' document on this mail server contains a list of
    security related APARs.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-18 OpenSSH Vulnerabilities in Challenge Response
    Handling

    There are two related vulnerabilities in the challenge response
    handling code in OpenSSH versions 2.3.1p1 through 3.3. They may allow
    a remote intruder to execute arbitrary code as the user running sshd
    (often root). The first vulnerability affects OpenSSH versions 2.9.9
    through 3.3 that have the challenge response option enabled and that
    use SKEY or BSD_AUTH authentication. The second vulnerability affects
    PAM modules using interactive keyboard authentication in OpenSSH
    versions 2.3.1p1 through 3.3, regardless of the challenge response
    option setting. Additionally, a number of other possible security
    problems have been corrected in OpenSSH version 3.4.

    IBM's AIX operating system does not ship with OpenSSH; however,
    OpenSSH is available for installation on AIX via the Linux Affinity
    Toolkit. The version included on the CD containing the Toolkit is
    vulnerable to the latest discovered vulnerability discussed here as is
    the version of OpenSSH available for downloading from the IBM Linux
    Affinity website. Anyone running this version is advised to follow the
    recommendations above to limit their vulnerability.

    We working with the changes for version 3.4 and will have a new
    package availble for download as soon as possible. When available the
    new packages can be downloaded from:

         http://www6.software.ibm.com/dl/aixtbx/aixtbx-p

    This site contains Linux Affinity applications containing
    cryptographic algorithms, and new users of this site are asked to
    register first.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability

    There is a remotely exploitable vulnerability in the handling of large
    chunks of data in web servers that are based on Apache source code.
    This vulnerability is present by default in configurations of Apache
    web servers versions 1.3 through 1.3.24 and versions 2.0 through
    2.0.36. The impact of this vulnerability is dependent upon the
    software version and the hardware platform the server is running on.

    IBM makes the Apache Server availble for AIX customers as a software
    package under the AIX-Linux Affinity initiative. This package is
    included on the AIX Toolbox for Linux Applications CD, and can be
    downloaded via the IBM Linux Affinity website. The currently available
    version of Apache Server is susceptible to the vulnerability described
    here. We will update our Apache Server offering shortly to version
    1.3.23, including the patch for this vulnerability; this update will
    be made available for downloading by accessing this URL:

      http://www-1.ibm.com/servers/aix/products/aixos/linux/download.html

    and following the instructions presented there.

    Please note that Apache Server, and all Linux Affinity software, is
    offered on an "as-is" basis. IBM does not own the source code for this
    software, nor has it developed and fully tested this code. IBM does
    not support these software packages.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-15 Denial-of-Service Vulnerability in ISC BIND 9

    AIX is not vulnerable.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-12 Format String Vulnerability in ISC DHCPD

    AIX is not vulnerable.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-11 Heap Overflow in Cachefs Daemon (cachefsd)

    AIX is not vulnerable.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-10 Format String Vulnerability in rpc.rwalld

    AIX 4.3 and 5.1 are not vulnerable.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-07 Double Free Bug in zlib Compression Library
    (Updated 3/29/2002)

    IBM's AIX operating system, version 5.1, ships with open
    source-originated zlib that is used with the Redhat Package Manager
    (rpm) to install applications that are included in the AIX-Linux
    Affinity Toolkit. zlib (libz.a) is a shared library in AIX. AIX 5.1 is
    susceptible to the described vulnerability. AIX 4.3.x does not ship
    with zlib, but customers who install zlib and use it will be similarly
    vulnerable.

    An updated rpm.rte install image for AIX 5.1 can be obtained from:

     ftp://ftp.software.ibm.com/aix/freeSoftware/aixtoolbox/INSTALLP/ppc/

    Customers that have installed zlib from the AIX-Linux Affinity Toolkit
    CD can obtain an updated zlib RPM from:

     ftp://ftp.software.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/zlib/
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-06 Vulnerabilities in Various Implementations of the
                             RADIUS Protocol

    AIX is not vulnerable.
    ===============================================================================
    ===============================================================================
    CERT Advisory CA-2002-03: Multiple Vulnerabilities in Many
    Implementations of the Simple Network Management Protocol (SNMP)

    The AIX operating system is susceptible to the vulnerabilities
    tested for by the Oulu University PROTOS test suite for all
    levels of AIX 4.3.x prior to level 4.3.3.51, and AIX 5.1 prior
    to level 5.1.0.10. APARs were developed and made available last
    year that closed the vulnerabilities looked for by the test suite.
    For 4.3.x, the relevant APAR is #IY17630; for 5.1, the appropriate
    APAR is #IY20943.

    To see if your version and level of AIX is vulnerable, enter the
    command:

      lslpp -l bos.net.tcp.client

    If the "Level" stated is lower than those given above, your
    system is vulnerable, and you are urged to apply the appropriate
    APAR.

    AIX versions prior to 4.3 are also vulnerable, but these versions
    are no longer supported by IBM.
    ===============================================================================
    ===============================================================================