Re: [RHSA-2002:164-02] Stronghold 3: New release fixes vulnerabilities in OpenSSL, mod_ssl and mm
Steve Luzzi <[email protected]> Wed, 31 Jul 02 14:54:28 -0500 (CDT)
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
When I execute the compiled version of openssl in the latest patch it gives the same info as the former 3015 release: OpenSSL> version OpenSSL 0.9.6b [engine] 9 Jul 2001 Is this version (3018) patched or not? Steve Luzzi ERDC-CERL > > --------------------------------------------------------------------- > Red Hat, Inc. Red Hat Security Advisory > > Synopsis: Stronghold 3: New release fixes vulnerabilities in OpenSSL, mod_ssl and mm > Advisory ID: RHSA-2002:164-02 > Issue date: 2002-07-31 > Updated on: 2002-07-31 > Product: Stronghold Cross Platform > Keywords: OpenSSL master session key mm temporary file mod_ssl overflow > Cross references: > Obsoletes: > CVE Names: CAN-2002-0653 CAN-2002-0655 CAN-2002-0656 CAN-2002-0658 CAN-2002-0659 > --------------------------------------------------------------------- > > 1. Topic: > > A new Stronghold 3 release is available which fixes several serious buffer > overflow vulnerabilities in OpenSSL, and local privilege escalation > vulnerabilities in MM and mod_ssl. > > 2. Relevant releases/architectures: > > > > 3. Problem description: > > OpenSSL is a commercial-grade, full-featured, and Open Source toolkit which > implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer > Security (TLS v1) protocols as well as a full-strength general purpose > cryptography library. A security audit of the OpenSSL code sponsored by > DARPA found several buffer overflows in OpenSSL which affect versions 0.9.7 > and 0.9.6d and earlier: > > 1. The master key supplied by a client to an SSL version 2 server could be > oversized, causing a stack-based buffer overflow. This issue is remotely > exploitable. Services that have SSLv2 disabled would not be vulnerable to > this issue. (CAN-2002-0656) > > 2. The SSLv3 session ID supplied to a client from a malicious server could > be oversized and overrun a buffer. This issue looks to be remotely > exploitable. (CAN-2002-0656) > > 3. Various buffers used for storing ASCII representations of integers were > too small on 64 bit platforms. This issue may be exploitable. (CAN-2002-0655) > > A further issue was found in OpenSSL 0.9.7 that does not affect versions of > OpenSSL included in Stronghold (CAN-2002-0657). > > The MM library provides an abstraction layer which allows related processes > to easily share data. On systems where shared memory or other > inter-process communication mechanisms are not available, the MM library > will emulate them using temporary files. MM is used in Stronghold to > providing shared memory pools to Apache modules. > > Versions of MM up to and including 1.1.3 open temporary files in an unsafe > manner, allowing a malicious local user to cause an application which uses > MM to overwrite any file to which it has write access. (CAN-2002-0658) > > All users are advised to upgrade to the new release which contains a > patched version of MM that is not vulnerable to this issue. > > The mod_ssl module provides strong cryptography for the Apache Web > server via the Secure Sockets Layer (SSL) and Transport Layer Security > (TLS) protocols. Versions of mod_ssl prior to 2.8.10 are subject to a > single NUL byte overflow that can cause arbitrary code execution. > (CAN-2002-0653) > > In order to exploit this vulnerability, the Apache Web server has to be > configured to allow overriding of configuration settings on a per-directory > basis, and untrusted local users must be able to modify a directory in > which the server is configured to allow overriding. The local attacker may > then become the user that Apache is running as (usually 'www' or 'nobody'). > > Thanks go to the OpenSSL team, Ben Laurie, and Marcus Meissner for > providing patches for these issues. > > 4. Solution: > > We have backported the security fixes for the versions of OpenSSL, mod_ssl > and mm included in Stronghold 3. Stronghold 3.0 build code 3018 is now > available which includes these fixes, and can be downloaded from > http://stronghold.redhat.com/sh3/ > > For information on how to upgrade between releases of Stronghold 3.0, see > http://stronghold.redhat.com/support/upgrade-sh3.xml > > 5. Bug IDs fixed (http://bugzilla.redhat.com/bugzilla for more info): > > > > 6. RPMs required: > > > > 7. Verification: > > MD5 sum Package Name > -------------------------------------------------------------------------- > > > These packages are GPG signed by Red Hat, Inc. for security. Our key > is available at: > http://www.redhat.com/about/contact/pgpkey.html > > You can verify each package with the following command: > rpm --checksig <filename> > > If you only wish to verify that each package has not been corrupted or > tampered with, examine only the md5sum with the following command: > rpm --checksig --nogpg <filename> > > 8. References: > > > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0653 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0655 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0656 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0658 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0659 > > > > Copyright(c) 2000, 2001, 2002 Red Hat, Inc. > > > > _______________________________________________ > Stronghold-users mailing list > [email protected] > https://listman.redhat.com/mailman/listinfo/stronghold-users >