Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > May 2005 > Two Sun Alert Notifications: 1. 57771 - A Limited Number of Sun StorEdge 6130 Arrays May be Vulnerable to Unauthorized Access 2. 57780 - NIS+ Client Users May Be Able to Cause a Denial of NIS+ Service

May 2005

Two Sun Alert Notifications: 1. 57771 - A Limited Number of Sun StorEdge 6130 Arrays May be Vulnerable to Unauthorized Access 2. 57780 - NIS+ Client Users May Be Able to Cause a Denial of NIS+ Service

ID: 00388
Ref: 358/2005
Date: 09 May 2005:15:43:01
Version: 1

Title: Two Sun Alert Notifications: 1. 57771 - A Limited Number of Sun StorEdge 6130 Arrays May be Vulnerable to Unauthorized Access 2. 57780 - NIS+ Client Users May Be Able to Cause a Denial of NIS+ Service
Abstract:
Vendors affected: Sun
Operating systems affected: Sun
Applications affected: Sun

Title
=====

Two Sun Alert Notifications:

1. 57771 - A Limited Number of Sun StorEdge 6130 Arrays May be
Vulnerable to Unauthorized Access

2. 57780 - NIS+ Client Users May Be Able to Cause a Denial of NIS+ Service

Detail
======

1. A local or remote unprivileged user may be able to gain
unauthorized access to a limited number of Sun StorEdge 6130 arrays
(SE6130). With this access, the user could delete data on the array.

2. Remote unprivileged users on NIS+ client systems may be able
to disable the NIS+ service daemon, rpc.nisd(1M) which runs on NIS+
servers and implements the NIS+ service. By disabling the
rcp.nisd(1M), the NIS+ service will be unavailable which is a type of
denial of service. If a NIS+ server is configured as a client as well
then local unprivileged users on that NIS+ server may be able to
disable rpc.nisd(1M). It is also possible that a poorly written client
application could similarly cause the denial of service.



1.




- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================


ESB-2005.0371 -- Sun Alert Notification 57771
A Limited Number of Sun StorEdge 6130 Arrays May be
Vulnerable to Unauthorized Access
9 May 2005

===========================================================================



Product: Sun StorEdge 6130 Array (SE6130)
Publisher: Sun Microsystems
Impact: Delete Arbitrary Files
Access: Remote/Unauthenticated

Original Bulletin:
http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-57771-1

- - --------------------------BEGIN INCLUDED TEXT--------------------

Sun(sm) Alert Notification
* Sun Alert ID: 57771
* A Limited Number of Sun StorEdge 6130 Arrays May be Vulnerable to
Unauthorized Access
* Category: Security
* Product: Sun StorEdge 6130 Array (SE6130)
* BugIDs: 6244556
* Avoidance: Workaround
* State: Resolved
* Date Released: 05-May-2005
* Date Closed: 05-May-2005
* Date Modified:

1. Impact A local or remote unprivileged user may be able to gain
unauthorized access to a limited number of Sun StorEdge 6130 arrays
(SE6130). With this access, the user could delete data on the array.

2. Contributing Factors This issue can occur on the following
platform:

* Sun StorEdge 6130 arrays with a serial number in the range of
0451AWF00G - 0513AWF00J

Notes:

1. The described issue only affects Controller Arrays. Expansion
trays are not affected.
2. SE6130 Controller Arrays with serial numbers outside the range
above are not impacted by this issue.

The Sun StorEdge Configuration Service (SSCS) commands can be used to
determine the serial number of a Sun StorEdge 6130 array as shown in
the example below:

1. Login to SSCS using the sscs(1M) comand line utility:

% /opt/se6x20/cli/bin/sscs login -h -u


2. To list the array(s) managed by this management host:

% /opt/se6x20/cli/bin/sscs list array
Array: SE6130-1
Array: SE6130-2
Array: SE6130-3

3. To list the details (including the serial number) of each array:

% /opt/se6x20/cli/bin/sscs list array
Array:
Serial Number: SUN.54062390100.0428AWF006
Firmware Version: 06.12.03.10
Array WWN: 60:0A:0B:80:00:16:AB:12:00:00:00:00:41:23:4B:E2
Node WWN: 20:04:00:A0:B8:16:AB:12
Default Host Type: Solaris (with Traffic Manager)
Default Cache Block Size: 16384
Default Cache Start %: 80
Default Cache Stop %: 80
Disk Scrubbing: 30 days
Failover Alert Delay: 5 minutes
Hot Spare Pool Disks: 1
Health OK
Tray ID: 1
Host: host 1
Pool: Pool 1-1
Pool: Pool 2
Pool: Pool 3
Pool: Pool 1
Pool: Default
%

4. Logout of SSCS

% /opt/se6x20/cli/bin/sscs logout

3. Symptoms There are no predictable symptoms that would indicate the
described issue has been exploited.

Solution Summary

4. Relief/Workaround There is no workaround. Please see the
"Resolution" section below.

5. Resolution Customers with an array that falls within the serial
number range defined above should contact their Sun authorized service
provider and reference this Sun Alert to obtain a utility which will
resolve this issue.

This Sun Alert notification is being provided to you on an "AS IS"
basis. This Sun Alert notification may contain information provided by
third parties. The issues described in this Sun Alert notification may
or may not impact your system(s). Sun makes no representations,
warranties, or guarantees as to the information contained herein. ANY
AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION
WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR
NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT
YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT,
INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE
OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN.
This Sun Alert notification contains Sun proprietary and confidential
information. It is being provided to you pursuant to the provisions of
your agreement to purchase services from Sun, or, if you do not have
such an agreement, the Sun.com Terms of Use. This Sun Alert
notification may only be used for the purposes contemplated by these
agreements.

Copyright 2000-2005 Sun Microsystems, Inc., 4150 Network Circle, Santa
Clara, CA 95054 U.S.A. All rights reserved.


- - --------------------------END INCLUDED TEXT--------------------

iQCVAwUBQn8DwSh9+71yA2DNAQJyKAQAlvg61kYdmABoFLzFpYn9u3Kq6veLCYpq
LXibHrUHD6FfPtHdXrvRCCQbaZNb/emVztfgfXKJssswlqr2z80V+FzlN/bxm8qo
4VApP9YMLkoZ1IztVQO4RLZenPT35UMiP7R7lUwALoTuwpnmdUVrrzCnAjUxcULB
9qpwRtZHlRI=
=N1Ni
- -----END PGP SIGNATURE-----


2.


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================

ESB-2005.0372 -- Sun Alert Notification 57780
NIS+ Client Users May Be Able to Cause a Denial of NIS+ Service
9 May 2005

===========================================================================



Product: Solaris
Publisher: Sun Microsystems
Operating System: Solaris 9
Solaris 8
Solaris 7
Impact: Denial of Service
Access: Remote/Unauthenticated

Original Bulletin:
http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-57780-1

- - --------------------------BEGIN INCLUDED TEXT--------------------

Sun(sm) Alert Notification
* Sun Alert ID: 57780
* Synopsis: NIS+ Client Users May Be Able to Cause a Denial of NIS+
Service
* Category: Security
* Product: Solaris
* BugIDs: 5109439
* Avoidance: Patch, Workaround
* State: Resolved
* Date Released: 04-May-2005
* Date Closed: 04-May-2005
* Date Modified:

1. Impact Remote unprivileged users on NIS+ client systems may be able
to disable the NIS+ service daemon, rpc.nisd(1M) which runs on NIS+
servers and implements the NIS+ service. By disabling the
rcp.nisd(1M), the NIS+ service will be unavailable which is a type of
denial of service. If a NIS+ server is configured as a client as well
then local unprivileged users on that NIS+ server may be able to
disable rpc.nisd(1M). It is also possible that a poorly written client
application could similarly cause the denial of service.

2. Contributing Factors This issue can occur in the following
releases:

SPARC Platform

* Solaris 7 without patches 106938-09 and 106942-29
* Solaris 8 without patch 108993-45
* Solaris 9 without patch 113319-22

x86 Platform

* Solaris 7 without patches 106939-09 and 106943-29
* Solaris 8 without patch 108994-45
* Solaris 9 without patch 113719-16

Notes:

1. This issue only affects systems that are configured as NIS+ Master
or Replica servers.
2. Solaris 10 is not affected by this issue.

To determine if this is a NIS+ Master or Replica server, the following
command can be run:

$ pgrep rpc.nisd || echo "This system is not a NIS+ server."

Also check that the rpc.nisd(1M) process is started on the system
(otherwise the system does not function as a NIS+ server). The
following command will show the running NIS+ service daemon
rpc.nisd(1M):

# ps -ef |grep rpc.nisd

3. Symptoms For Solaris 7 and 8 this can effectively disable the NIS+
service for that server. If the request is repeated, then another
server will be disabled until all NIS+ services are disabled. For
Solaris 9 the server will consume excessive CPU time executing a tight
loop, but the NIS+ service will continue. Should sufficient requests
be made the server will effectively become disabled.

This could affect for example, login of a user to a client system, a
request to the NIS+ naming service with commands like nisls(1) or
getent(1M) or telnet(1) to another system.

In addition, NIS+ servers will be showing continuous high CPU usage.
This means that the output of the "ps -efl" command will show a fast
increasing number for the used time of the rpc.nisd(1M) process.

Solution Summary

4. Relief/Workaround To temporarily work around the described issue:
restart the NIS+ server daemon, then by using snoop(1M), identify the
source of the requests and either discontinue or disable it, if
possible.

5. Resolution This issue is addressed in the following releases:

SPARC Platform

* Solaris 7 with patches 106938-09 or later and 106942-29 or
later
* Solaris 8 with patch 108993-45 or later
* Solaris 9 with patch 113319-22 or later

x86 Platform

* Solaris 7 with patches 106939-09 or later and 106943-29 or
later
* Solaris 8 with patch 108994-45 or later
* Solaris 9 with patch 113719-16 or later

This Sun Alert notification is being provided to you on an "AS IS"
basis. This Sun Alert notification may contain information provided by
third parties. The issues described in this Sun Alert notification may
or may not impact your system(s). Sun makes no representations,
warranties, or guarantees as to the information contained herein. ANY
AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION
WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR
NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT
YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT,
INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE
OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN.
This Sun Alert notification contains Sun proprietary and confidential
information. It is being provided to you pursuant to the provisions of
your agreement to purchase services from Sun, or, if you do not have
such an agreement, the Sun.com Terms of Use. This Sun Alert
notification may only be used for the purposes contemplated by these
agreements.

Copyright 2000-2005 Sun Microsystems, Inc., 4150 Network Circle, Santa
Clara, CA 95054 U.S.A. All rights reserved.


- - --------------------------END INCLUDED TEXT--------------------


iQCVAwUBQn8FUCh9+71yA2DNAQI0zQP/dtgDLaUhQ+jQW1dlu6+DbFfqSgIl4eGb
dvtlGWbRLLWaXMcfnuwH2UKXVMaBgzNlQPkgMWDkWbrR1jvSvIGtYrm6EXTrfqmL
9Kx2a3RCVKVYU01zIHOkEBODI12qgwPqNX7BsHaQ7ZHVJtgs1aW5scqUOSGdpXuy
hqr5gxfZuKI=
=oKNd
- -----END PGP SIGNATURE-----
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |