1. /
  2. Security Response/
  3. Pam_SMB Remote Buffer Overflow Vulnerability

Pam_SMB Remote Buffer Overflow Vulnerability

Risk

High

Date Discovered

August 26, 2003

Description

pam_smb has been reported prone to a buffer overflow vulnerability. It has been reported that systems using pam_smb to authenticate to a remotely accessible service may be vulnerable to a condition that could allow a remote attacker to supply and execute arbitrary code in the context of the vulnerable module.

Technologies Affected

  • RedHat pam_smb-1.1.6-2.i386.rpm
  • RedHat pam_smb-1.1.6-2.ia64.rpm
  • RedHat pam_smb-1.1.6-5.i386.rpm
  • RedHat pam_smb-1.1.6-7.i386.rpm
  • SGI ProPack 2.2.1
  • SGI ProPack 2.3.0
  • Sun Linux 5.0.7
  • pam_smb pam_smb 1.1.0
  • pam_smb pam_smb 1.1.1
  • pam_smb pam_smb 1.1.2
  • pam_smb pam_smb 1.1.3
  • pam_smb pam_smb 1.1.4
  • pam_smb pam_smb 1.1.5
  • pam_smb pam_smb 1.1.6
  • pam_smb pam_smb 2.0.0 -rc4

Recommendations

Block external access at the network boundary, unless external parties require service.

Restrict access to the affected server at the network perimeter. Allow communications from trusted hosts and networks only. Deny all other communications.

Implement multiple redundant layers of security.

An attacker's ability to exploit this vulnerability to execute arbitrary code may be hindered through the use of various memory protection schemes. Where possible, implement the use of non-executable and randomly mapped memory segments.
Sun have released fixes to address this vulnerability in Sun Linux 5.0.7. Users who are affected by this issue are advised to apply relevant fixes as soon as possible. Please see Sun reference (Sun Linux Support - Sun Linux Patches (Sun)) for further details regarding obtaining and applying appropriate fixes. Red Hat has released a security advisory (RHSA-2003-262) to address this issue for enterprise customers. Further information regarding obtaining and applying fixes can be found in the referenced advisory. Red Hat has released a security advisory (RHSA-2003:261-01) to address this issue. Customers who are affected by this issue are advised to apply the relevant fixes as soon as possible. Fixes are linked below. Further information regarding applying fixes can be found in the referenced advisory. Debian has released an advisory (DSA 374-1) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes. Turbolinux has released an advisory (TLSA-2003-50) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes. Gentoo Linux has released a security advisory (200309-01) to address this issue. Users who are affected by this issue are advised to do the following: emerge sync emerge pam_smb emerge clean SuSE has released an advisory (SuSE-SA:2003:036) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes. Conectiva has released an advisory (CLSA-2003:733) that addresses this issue. Please see references for details on obtaining and applying fixes. Conectiva has released an advisory (CLSA-2003:734) containing updated packages that addresses this issue. Please see references for details on obtaining and applying fixes. SGI has released an advisory (20031002-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10027) containing updated RPM packages relating to 22 different BIDS. Patch 10027 can be obtained via the following link: http://support.sgi.com/ For information regarding how to obtain individual RPM packages included in Patch 10027, please see the attached advisory. pam_smb have released a stable upgrade to address this issue:

Credits

Discovery of this vulnerability has been credited to Craig Miskell.
Copyright © Symantec Corporation.
Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Security Response. Reprinting the whole or part of this alert in any medium other than electronically requires permission from secure@symantec.com.

Disclaimer
The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.
Symantec, Symantec products, Symantec Security Response, and secure@symantec.com are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.

Threat Intelligence

Subscribe
Follow the Threat Intelligence Twitter feed
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver