From: UNIRAS (UK Govt CERT) [uniras@niscc.gov.uk] Sent: 29 September 2003 10:56 To: uniras@niscc.gov.uk Cc: interim@lists.niscc.gov.uk Subject: UNIRAS Brief - 544/03 - SGI - DCE 1.2.2c Denial of Service Vulnerability -----BEGIN PGP SIGNED MESSAGE----- - ---------------------------------------------------------------------------------- UNIRAS (UK Govt CERT) Briefing Notice - 544/03 dated 29.09.03 Time: 10:56 UNIRAS is part of NISCC(National Infrastructure Security Co-ordination Centre) - ---------------------------------------------------------------------------------- UNIRAS material is also available from its website at www.uniras.gov.uk and Information about NISCC is available from www.niscc.gov.uk - ---------------------------------------------------------------------------------- Title ===== SGI Security Advisory: DCE 1.2.2c Denial of Service Vulnerability Detail ====== - - -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SGI Security Advisory Title : DCE 1.2.2c Denial of Service Vulnerability Number : 20030902-01-P Date : September, 26 2003 Reference : CVE CAN-2003-0746 Reference : SGI BUG 897593 Fixed in : Patches 5313/5314 for DCE 1.2.2c ______________________________________________________________________________ SGI provides this information freely to the SGI user community for its consideration, interpretation, implementation and use. SGI recommends that this information be acted upon as soon as possible. SGI provides the information in this Security Advisory on an "AS-IS" basis only, and disclaims all warranties with respect thereto, express, implied or otherwise, including, without limitation, any warranty of merchantability or fitness for a particular purpose. In no event shall SGI be liable for any loss of profits, loss of business, loss of data or for any indirect, special, exemplary, incidental or consequential damages of any kind arising from your use of, failure to use or improper use of any of the instructions or information in this Security Advisory. ______________________________________________________________________________ - - - ----------------------- - - - --- Issue Specifics --- - - - ----------------------- It has been reported that certain Microsoft RPC scanning can cause the DCE daemon dced to abort, causing a denial of service vulnerability. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0746 to this issue: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0746 SGI has investigated the issue and recommends the following steps for neutralizing the exposure. It is HIGHLY RECOMMENDED that these measures be implemented on ALL vulnerable SGI systems. This vulnerability has been corrected with patches to DCE 1.2.2c and in potential future releases of DCE. - - - -------------- - - - --- Impact --- - - - -------------- DCE is an optional product, not installed by default. To determine the version of DCE you are running, execute the following command: % versions -b dce dce_domestic This will return a result similar to the following output: I = Installed, R = Removed Name Date Description I dce 08/01/2003 Distributed Computing Environment, 1.2.2c I dce_domestic 08/01/2003 Distributed Computing Environment(domestic), 1.2.2c If the output is similar to the above, then DCE is installed and the system may be vulnerable unless patched. - - - ---------------------------- - - - --- Temporary Workaround --- - - - ---------------------------- There is no effective workaround available for this vulnerability. SGI recommends either upgrading DCE (when available), or installing the appropriate patch from the listing below. - - - ---------------- - - - --- Solution --- - - - ---------------- SGI has provided a series of patches for this vulnerability. Our recommendation is to upgrade DCE (when available), or install the appropriate patch. For international version of DCE 1.2.2c, install patch 5313. For domestic version of DCE 1.2.2c, install both patch 5313 and 5314. Note that, for export control reasons, the domestic patch 5314 will not be made available on the patches.sgi.com FTP site, and must be obtained from your SGI support representative. Older versions of DCE are potentially vulnerable, but are no longer supported. No patches are available for older unsupported DCE releases. ##### Patch File Checksums #### Filename: README.patch.5313 Algorithm #1 (sum -r): 54174 9 README.patch.5313 Algorithm #2 (sum): 30234 9 README.patch.5313 MD5 checksum: E0307B53001243D5A87FAA74CEBCFDAA Filename: patchSG0005313 Algorithm #1 (sum -r): 14338 4 patchSG0005313 Algorithm #2 (sum): 54694 4 patchSG0005313 MD5 checksum: 3153FD44926CDE616A2A82E86FDBCD09 Filename: patchSG0005313.dce_man Algorithm #1 (sum -r): 35638 7 patchSG0005313.dce_man Algorithm #2 (sum): 2968 7 patchSG0005313.dce_man MD5 checksum: 0333479CE3C5652B6E232422B5C451DD Filename: patchSG0005313.dce_sw Algorithm #1 (sum -r): 21490 6527 patchSG0005313.dce_sw Algorithm #2 (sum): 5488 6527 patchSG0005313.dce_sw MD5 checksum: 51E65B0D9FC72DF3817BC55A514437C2 Filename: patchSG0005313.dce_sw32 Algorithm #1 (sum -r): 41987 6716 patchSG0005313.dce_sw32 Algorithm #2 (sum): 42956 6716 patchSG0005313.dce_sw32 MD5 checksum: 5EFF27658E973E86A491BB2AA4404734 Filename: patchSG0005313.dce_sw64 Algorithm #1 (sum -r): 17548 6823 patchSG0005313.dce_sw64 Algorithm #2 (sum): 32727 6823 patchSG0005313.dce_sw64 MD5 checksum: 352B116D7FC928F1CEF08CC3CB7D2347 Filename: patchSG0005313.idb Algorithm #1 (sum -r): 01470 2 patchSG0005313.idb Algorithm #2 (sum): 10197 2 patchSG0005313.idb MD5 checksum: 5B9F9B37B28F84D6FF63ADCE14B0A05F Filename: README.patch.5314 Algorithm #1 (sum -r): 02572 9 README.patch.5314 Algorithm #2 (sum): 34329 9 README.patch.5314 MD5 checksum: B5C48AC12B403AB7F43769659F3A5762 Filename: patchSG0005314 Algorithm #1 (sum -r): 35912 5 patchSG0005314 Algorithm #2 (sum): 21082 5 patchSG0005314 MD5 checksum: A056DE501167973DC0C1765BA59F566D Filename: patchSG0005314.dce_domestic_sw Algorithm #1 (sum -r): 48466 6591 patchSG0005314.dce_domestic_sw Algorithm #2 (sum): 17258 6591 patchSG0005314.dce_domestic_sw MD5 checksum: 12FDB6C36AA931FCF7147594F3C547EF Filename: patchSG0005314.dce_domestic_sw32 Algorithm #1 (sum -r): 39925 6822 patchSG0005314.dce_domestic_sw32 Algorithm #2 (sum): 39342 6822 patchSG0005314.dce_domestic_sw32 MD5 checksum: C50E8D2F8F2E07FDB0EDABC02639D5AA Filename: patchSG0005314.dce_domestic_sw64 Algorithm #1 (sum -r): 09209 6916 patchSG0005314.dce_domestic_sw64 Algorithm #2 (sum): 62264 6916 patchSG0005314.dce_domestic_sw64 MD5 checksum: 78379D662001023EAA7A8DEE23067750 Filename: patchSG0005314.idb Algorithm #1 (sum -r): 51607 2 patchSG0005314.idb Algorithm #2 (sum): 11196 2 patchSG0005314.idb MD5 checksum: 0B791839259EDCD27CB02577421ABF5B - - - ------------------------ - - - --- Acknowledgments ---- - - - ------------------------ SGI wishes to thank Lawrence Livermore National Labs for their assistance in this matter. - - - ------------- - - - --- Links --- - - - ------------- SGI Security Advisories can be found at: http://www.sgi.com/support/security/ and ftp://patches.sgi.com/support/free/security/advisories/ SGI Security Patches can be found at: http://www.sgi.com/support/security/ and ftp://patches.sgi.com/support/free/security/patches/ SGI patches for IRIX can be found at the following patch servers: http://support.sgi.com/ and ftp://patches.sgi.com/ SGI freeware updates for IRIX can be found at: http://freeware.sgi.com/ SGI patches and RPMs for Linux can be found at: http://support.sgi.com SGI patches for Windows NT or 2000 can be found at: http://support.sgi.com/ IRIX 5.2-6.4 Recommended/Required Patch Sets can be found at: http://support.sgi.com/ and ftp://patches.sgi.com/support/patchset/ IRIX 6.5 Maintenance Release Streams can be found at: http://support.sgi.com/ IRIX 6.5 Software Update CDs can be obtained from: http://support.sgi.com/ The primary SGI anonymous FTP site for security advisories and patches is patches.sgi.com. Security advisories and patches are located under the URL ftp://patches.sgi.com/support/free/security/ For security and patch management reasons, ftp.sgi.com (mirrors patches.sgi.com security FTP repository) lags behind and does not do a real-time update. - - - ----------------------------------------- - - - --- SGI Security Information/Contacts --- - - - ----------------------------------------- If there are questions about this document, email can be sent to security-info@sgi.com. ------oOo------ SGI provides security information and patches for use by the entire SGI community. This information is freely available to any person needing the information and is available via anonymous FTP and the Web. The primary SGI anonymous FTP site for security advisories and patches is patches.sgi.com. Security advisories and patches are located under the URL ftp://patches.sgi.com/support/free/security/ The SGI Security Headquarters Web page is accessible at the URL: http://www.sgi.com/support/security/ For issues with the patches on the FTP sites, email can be sent to security-info@sgi.com. For assistance obtaining or working with security patches, please contact your SGI support provider. ------oOo------ SGI provides a free security mailing list service called wiretap and encourages interested parties to self-subscribe to receive (via email) all SGI Security Advisories when they are released. Subscribing to the mailing list can be done via the Web (http://www.sgi.com/support/security/wiretap.html) or by sending email to SGI as outlined below. % mail wiretap-request@sgi.com subscribe wiretap end ^d In the example above, is the email address that you wish the mailing list information sent to. The word end must be on a separate line to indicate the end of the body of the message. The control-d (^d) is used to indicate to the mail program that you are finished composing the mail message. ------oOo------ SGI provides a comprehensive customer World Wide Web site. This site is located at http://www.sgi.com/support/security/ . ------oOo------ If there are general security questions on SGI systems, email can be sent to security-info@sgi.com. For reporting *NEW* SGI security issues, email can be sent to security-alert@sgi.com or contact your SGI support provider. A support contract is not required for submitting a security report. ______________________________________________________________________________ This information is provided freely to all interested parties and may be redistributed provided that it is not altered in any way, SGI is appropriately credited and the document retains and includes its valid PGP signature. - - -----BEGIN PGP SIGNATURE----- Version: 2.6.2 iQCVAwUBP3Rpm7Q4cFApAP75AQElOQP+O/yzZPfiUaJ6SjJOzAKUDOTZRdi1gL9V 11AwzNjxjGxdEza4JGbfW3j7VKEM8iKhA6RjmwWZgfm0DgTib87f5/tMYesOYryW W4/b/wm6zXyevWUGqQTG+x/rO9RPmcqBFuxUCA3RMLBGJh3QAxsrDQwAiguOuf2C 6Sfy57y3CeY= =T+dI - - -----END PGP SIGNATURE----- - ---------------------------------------------------------------------------------- For additional information or assistance, please contact the HELP Desk by telephone or Not Protectively Marked information may be sent via EMail to: uniras@niscc.gov.uk Office Hours: Mon - Fri: 08:30 - 17:00 Hrs Tel: +44 (0) 20 7821 1330 Ext 4511 Fax: +44 (0) 20 7821 1686 Outside of Office Hours: On Call Duty Officer: Tel: +44 (0) 20 7821 1330 and follow the prompts - ---------------------------------------------------------------------------------- UNIRAS wishes to acknowledge the contributions of SGI for the information contained in this Briefing. - ---------------------------------------------------------------------------------- This Briefing contains the information released by the original author. Some of the information may have changed since it was released. If the vulnerability affects you, it may be prudent to retrieve the advisory from the canonical site to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by UNIRAS or NISCC. The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. Neither UNIRAS or NISCC shall also accept responsibility for any errors or omissions contained within this briefing notice. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this notice. UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large. - ---------------------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: PGP 8.0 iQCVAwUBP3gBo4pao72zK539AQF/jwQAr6YB4UOgs3h4ba3KMyElr+sW+vkdX/j+ vt9ShMGkey5EQRe6aaIwCl1RPjEYMd3draY7fAgI8GSCPX9Ef30pEWMdQ6oncqjE WLPVTX83qlAWVUZxU013xbT3uL+Ou+oUjvFavPkOI6lNxsmTY/irACK0a0jj+u01 c0jTnqiRlek= =TzkJ -----END PGP SIGNATURE-----