8275816 2002-04-11 20:22 +0200  /35 rader/ Paul Starzetz <paul@starzetz.de>
Sänt av: joel@lysator.liu.se
Importerad: 2002-04-12  03:04  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Extern mottagare: Roman Drahtmueller <draht@suse.de>
Mottagare: Bugtraq (import) <21821>
Ärende: Inn (Inter Net News) security problems
------------------------------------------------------------
From: Paul Starzetz <paul@starzetz.de>
To: bugtraq@securityfocus.com, Roman Drahtmueller <draht@suse.de>
Message-ID: <3CB5D449.9050504@starzetz.de>

Hi,

I found several problems inside the inn (<=2.2.3) package as shipped
with various Linux distributions. There are several format string
coding bugs as well as unsecure open() calls. In particular the inews
and the rnews binaries are affected. This may lead to serious
security problems if those binaries are installed set-uid and are
executable by any user.  In the case of inews, obtaining uid news is
possible (which can be further used to replace/trojan other system
files like the binaries themselves), in the case of rnews, access to
probably sensitive inn configuration files seems possible (like inn
password hashes etc).

The attached archive contains a short proof of concept code for one
of the format string bugs (look in the inews.sh script for more
details) in the inews binary. The code has been succesfully tested
against SuSE 7.0 where inews and rnews are setuid news. Later
distributions seems to use another security conecept - the binaries
are either only setgid news or are not runnable by ordinary
users. The exploitation is technically difficult - it requires a fake
NNTP server setup somewhere (the code comes with the tar
package). Note: this is NOT a remote exploit. Look at the code for
more technical details. The code will create a setuid news shell.

Vendors have been noticed more than 5 weeks ago.

regards,

/ih
(8275816) /Paul Starzetz <paul@starzetz.de>/(Ombruten)
Bilaga (application/octet-stream) i text 8275817
8275817 2002-04-11 20:22 +0200  /27 rader/ Paul Starzetz <paul@starzetz.de>
Bilagans filnamn: "innexpl.tar.gz"
Importerad: 2002-04-12  03:04  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Extern mottagare: Roman Drahtmueller <draht@suse.de>
Mottagare: Bugtraq (import) <21822>
Bilaga (text/plain) till text 8275816
Ärende: Bilaga (innexpl.tar.gz) till: Inn (Inter Net News) security problems
------------------------------------------------------------
‹në€<íZmWÛH²ž¯Ö¯è8Ø`lÉ6„˜{™àÌp†kȝì	Ž,µm¹¥Ñ†ÙÉߧº[²,L’=“™ýpÝ	¶Õ/ÕUÕõÖUÙ7\ˆ$l:?üeÍ´Ls§ÛýÁDÛÝQߖ~Fël›ø½ÛíìîîìtLó­ÝNçfþu(Í['vÄØ¡ú_žÇ£øï@èïm­ïԌJÖè÷[È;9¹8càÛ-Ø(ˆ˜'ø,nƓ|V”
æ%,¦|Æ'g÷AÊ&ö-g©çöÌ|æL‚8‰Y ü{–L8úö„£ 
óI…í¿Sk²=õ„ã§.g¯ãÄõ‚æd±Ë÷†å¾ÈãRß}܊ç†'‹ý©ðb±Oð¬JZžx#¹yü°{f{%À±7¶O}Ô<‘°©í‰ZÝø—|ˆÌîYf»Ó`~ƒE
&zæžÌS‡ű]7ºö‹=±g8(É0}ܶÚW˜ÎËö£bTÔfµó£ŸÎŽÎú
†×G?Ô÷hpø;‚šZÓ¼ßy0ҏõ:­Y)ÞÔÞ^ô/áôÍ/×çƒþÁ»3	7ªÅ¯ÍºQ©„<Š‚¨VUkªõãw^R³$0¿—í@‹¢ž…Ϙ'47“ZL ¯	¼ÚæzÐÞ?8<4Ø3ðÁ—PÎÏ@|Ž1~º U4ñw=²§¤±Ç4΅¡0ˆL’@Ä5Ëz©ø¡kè	—pX¹"IŒŠÒìò*Œ¡á‚YoªñEέV%œ9Ì·§œ]¼ÉÔÓ¨Ì&žÏ1‘ý`|:9nЊã1¯Ù	ã¶ãpÅOEË3_‰ÍM…&ádï›
`%„F$£ZõR²u—U!pr~e4òÓxRƒi¢¶ªÄzº˜jÛ4/A‹œ=‹¼X4˜’¥$òÁ-HŽ¸íÎGóQ`ôK„3
5èŸqð@¥[×hVäpxŸK+>6»e¡ÝRGAÛI=(^‘*U
Túÿxß?¿èƒô¸š©†Q¦ŸúpD°)—OŸéã¯âʸÖö¥X/…4±þM/E[-âý=·Áì]7adÜ¿„¦ßR/¹ß
úËÃ8ŽÏ†ñ$Ã96þÛ>üÏ´Ì%ÿ•{Pü·»½ýHü×no·;:þÛ5w:ÅÝmkÿýíé“œLkhÇã©ñ”]L8Â01‡_°}¸Á“Ž%F'Ã/.$ÒÈáX“L¼˜ÅNä…	›y¾Ÿúb6¨¥cÄ~©p™°QÃƅ·”Ü9¯°œZí6ðÜzAi¡xØvp´µ?M ‹Žð8†
ê
ñß,ˆ€ÝS|9Å*ô¢]%9?3"Cb¢±²/´:áÎDxŽíÉ;Á4ôñ;á.V¹)gI l‡è°Mömàßr—,Ãò EÆìšÀçcm°|¬-D0;u¼šÆ)6bÏ¥m!†'oÊãçßRâä;6M®ˆ9¨w™Z Ù€õHãv4N§œ"¹Ävn°Øðù¶+·ŸØb¬¦u"`{5>°`ÄlfÞuÍþ‰ÆýЉ¥a@!aNrÄ&Ül&…úÆÞ-Ø2ñŸóâ$ˆ$¯.$*ªŸÜbÌŽ"ã&øÂ})D˜r¦Ð7)ÀqjèÂó/K‰nÌü甜 ;À0ˆcoèÓb[
‹ˆL-·%tà èXx²…»#qÓ¸à,ýÀQb€•çïÏî
šì"`cž€^·'—Ð
Ež†Z

ð$¨K1c…¬FÂ4Qò(Մ´DýO½É~ònI$¥a˜†…ÏdÀE—´!-àq–专TÎ<È«­:(4äFC%ïęˆþèääÇ£“^+#©ÊrM¿'!Ñ=Œ.ø:ÐkÈ+–à8™( 	ÕÒ=š|¾RØjÐ
îׄ&ý³*©¢Ü_IYmjß³[Âiæ%µ-·tä³^PX©†1ߖJ±óô¼Ïv›&	±páþ%›žÇEDùh~3´Áñ˜Ë=d¯)ŠÉ}H5Eó=ón8‚–Ú¦IxkYpGb’	y¦
Ú@%oƒ™c\/âäûÞ(ÊF¯[¸ëµ2?j"[f<%•‡AØéHkÅÆAà‚kAàÁn¾;øp68ý±ßÛé0'ˆhWÅ#©°¤ê0–x`Ú0܀Çâ9„<ˆnhÈå#x®Äx{|tÖ3¥œ„P? a¤S;¾ap°LL ?XõO\‡«VlÇÐ%_Ëf®i™(µG@¨bŽ&ö?R>`Ïܶ—LYñg!†O¸sCU懃[òˆ=A†<m¥lMiۓ*oT$+jó[Wùxv"¸iaa+±6=U¬ÁŒYí—ÆÈCtZ8Œ›Wìíéû“ÃÜN)>B!5t zñîŒÄo­6½Iø4d[¸=µ’iMÄçæÙªuczÑe[![SkǝÿœL!|öf4»cM%pbĞe¶›Ìț·½ªžN°›4£j.ŽÞ÷çCt/h&wIu:—Ǽ»§·ž_5¢)Û±|=Q¸5³ã-ÒH1`‹Ùë×××ýÓ·××l?ÛÚ¢±-¼ß¥¥~U©À.‘¿EŽš¥;B4ðäDZwòŒd-C¨m‚5-ž8J_©Ó¢«’q„z0ü`lû«ÅY~0.õL’$,uáDJ=1ðõK}šÝq©›|Ü­Çgåî4Ã5—w·#g‡\êM…G`J½‚¨é"Íéq§ÈN±ýQyW®MúU:Ṅ|Y¾iŽ‡¼ÝCé2žVÈßBôcCPÒo­-ØJ¥©Q¡«^ÀwMέVÙä]‘îú
þ¤ö7ÆåV÷¾@ÁÞR2Û֓Û2åâäs$ÚD=:ü€èSÔ`'¹9Ì%üÝ/ïÎ&ŸÞL)à.ß<tOØZÑçH¡œäº{÷…Ñt3^:šojÀ¨íǯ»¾õìÕdEïƒóª‚Ž,(;bmÖ´9QÜÝÏYõ<~‚ÿ{%3»ÚÆïÆIÅe¾7~tʒ.7
íqàÛKgç&qŽðyhÛù{bà>OÓYš»]H¯Rº1âSƒhËïzƒå?ë{zÂXOÏ'Œ³	üŽ;~­š‹GµÁªúûäýñ1%9tÂj¿ D†¤aŒ‡)LÙV -´”²¯œ3nCžOM“¿®à4›B}9Y´’>bè0JU´çp²òhÁæ·I!䀗,°wyj}Iþa¶}YV}äˆÄ_ì¹¢my2²÷¸:>žgߐë,¯oG¡Mq{"á¨L­ºpÈ«ÌWÄÜàðÉéÙ¹º7Oøa‰ê²Ìv·ØƒËÔKŠzu¬îqÿ„m[íRW›u͗;zG|!øŽCîxꤘÆRj•FÐ5Ž¦Êx^âF–®Ù*Úºü8)‚Y¨Ä<’Æ"Ã}Á8j
#žz“å…lƒW½Jõò®c]Þ9¦úv‡úùeUfB1<Ä£‰¿á.¾Ûøîà»SÍF±°»ƒîåÝ3ë}d¶¦£!nkˆÖ
ñ$ŒX»å5;·»—wÛ½±èû¥z6	+¬vÛº;š»…ߣ|X9T½@³°¢Ì-s±vèjÈ/ðçÆðY× ¦Ú’Èèš²@¸Øz4Êþô9W÷H\ž”²©G(V“ç·1ÇÒüÍsýU]›z¦RìóA²7o.Ž_±õ˜m©Ô8`Ȕ«ªc¨uä3Œ‹Ú@È5á ¦?È«—ÐR…‘6Õf>C$5Rà§AÂçQ
×K.
…³è
eJÁ¨<öë[ß¿2•!ÍX~a
Ù#ù»V]“i€ê¼ŠE%$(ö#…¬y9JIGUOgs8Ëê4±(æîƒ[–®Ød’B³U²>ÖÉúíM:)t«jU¬7wÏôÃvÊàllØ·tª© ò%wu¯3ꑏm°pO®¹‚ûÔ`7
6ò½°ÁB÷#•>ó•2+A2`,LÈÏP! IA\™¢$	o?¨
¡í.ˆÐ"‚4ü±Ó¹Ò%=ÈlR2G+nkUºËž¼í­ÉK<·lHž@ð}\(ç§0:ÿ[a™žÉìøœ,œ?ÅG=n°ÐB=æF|÷
½rð¼ÑhT{Ic5	hŸ½`õ%s,‹&EË´;W½ÂNCۅ¡—‹C»…!À/ŽuvK‰'2Ud³)LBD9âðžR¨”ûV—š¢Mù¸qņ¶ºZà<
¬/"Uæ%I€b©Y¤EI½ 04*×:#0ÒHƒ%Í8¹&}`›Ìڑ ‰õAÈEÔéõàðôäøŸ²úME2_G²²õs¹úøÃ(@˜¡RÉ%ªhHƂ4Øl6Yès¦ø׃£*ªÁ“,£Óx½_„ާ׃÷'oæ:¼ÏÅBÞ4±_É X…Ÿ‹‹—”ëÀk z!¯…®¶L^Ñ4RÍç™{ì¾èež´&æVH?+3•DbçSª?¾9¬æѽô"óõ
«Âú9ÓS‘x>£Õ”9’µ’R9žÞ_ˆºT]8@ª"#«+_dv¹nº„Ý•/3œªì’“†*¦?¢ʷ1	ó>©÷	
2™É›ä˧_T9]¬tå$bO¦ú%c«º„KL`
&)^_oŽ××ïÔ¼¯P:Šï…£UhŽ [ov\pߓs蕃š·u­?BÅÃú¿^|SË^LÀE¶
þh^éhaÞe¡ËzØÕV]ú&™¥A¢L1ҏ-y­Ìî¾ó«eÏþ`p:`
F=¯Ÿ/ye¡M©7èUË>î핍Ҕ=ôøŠ·`G-ìÕüàFçÿúàºÝn§ÛîZÕzƲ0DrŃͰ$S°ty*.š¼=½¥‚ÿ¿ÒÍiݕÁ¥
f:ÄXʇ!ȹÉxðp!,¿‘µÕFØïÿrýæý@G¬EV¿%[­«zÁ7
½qVŐW2Y
™̬éP×ÈJ6«e™Ô«ÿº¾åÁpý¹H,3ë¸C(¯b;îšòã\Ы3ôÊu5òX¢`?UG½ì¼æ2X0Zggý“C9ÑðMæùæuîºêc§Þª•!o*lØÍæfý¡
Óàæ2dŠ¼_d®Ë¸ãx¦¸µÜéáh©p&ä‰)@¤@I—§ö‘æ€ýXXsJòR…VkÝCïš®¹y]b®œór¦<°Ë0zÕ\®î™í~"A’Å`„»ºHââùsˆBhqÏDÆÅTENT‰"ü
.LÇ©LY|™!åT‡%Ê
Š_62>åddt”}"nŠ/3k±Q§ˆ™jŸê]Mæ#Er„w`¹D7`ý£3•äYm܆zË2º®š,`֝c>ÞÈVû&kfs§'qþ´ÑݴڋîC‰UæÍ»õæ‹;ƈŸ°@òý+uË
N/õÊT.8ŽE;¬_“±çÃd±
DÛùËpeûxv088<ýðDáHë™À.–åžo\-}ËMúíÌ>«wº³z¬›!«»öÁ
G¿/ža'“ٛvs·§^b}.yXpúrúËóß-hš~%à#åوö Q듉ÈJ…ö-:
ébFkeD²nvÝ»uš_-œ}i×ìMЅÀ°DdËå·-‘Ât©k¯ƒBØ@€ÌÒ³UzþS1E9D(½E—å‚U;ÏS[?,æ±uç7§²³ù0Ý!¾9©­—ÑÕ^‚#‚Ù“ªa4[V2áòJëû•®U[µU[µU[µU[µU[µU[µU[µU[µU[µU[µU[µU[µU[µU[µUûØþ
ˆý‹¡P
(8275817) /Paul Starzetz <paul@starzetz.de>/(Ombruten)