[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference turris::digital_unix

Title:DIGITAL UNIX(FORMERLY KNOWN AS DEC OSF/1)
Notice:Welcome to the Digital UNIX Conference
Moderator:SMURF::DENHAM
Created:Thu Mar 16 1995
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:10068
Total number of notes:35879

8844.0. "ntalkd and NIS security questions" by MUNICH::CUZUM () Mon Feb 17 1997 05:03

Hi security-wizards,

a customer sent me some mail from CERT and wants to know which is
DIGITAL's position to following scurity holes:

1) talkd (ntalkd) -> Buffer Overrun vulnerability (intruders may be able
to execute arbitrary commands with root privileges, see AUSCERT Advisory
AA-97.01)

2) insufficiently protected NIS-domains  -> customer has been informed by 
DFN-CERT, University of Hamburg ( [email protected]) that there are some 
serious security holes concerning the protection of NIS-password-database. 
Some Unix-Systems (like Sun, HP and IBM) have released patches to protect 
the access on NIS-Servers (see /var/yp/securenets). Does anything similar 
exist for DIGITAL UNIX?

Customer needs an official statement on this security-problems. For more
information see: http://www.cert.org/ ,ftp://info.cert.org/pub/ or
e-mail me: [email protected].            

Thank-you in advance.

Regards,

Corina
                                
         
T.RTitleUserPersonal
Name
DateLines
8844.1SMURF::DANIELEMon Feb 17 1997 09:1114
>2) insufficiently protected NIS-domains  -> customer has been informed by 
>DFN-CERT, University of Hamburg ( [email protected]) that there are some 
>serious security holes concerning the protection of NIS-password-database. 
>Some Unix-Systems (like Sun, HP and IBM) have released patches to protect 
>the access on NIS-Servers (see /var/yp/securenets). Does anything similar 
>exist for DIGITAL UNIX?

NIS support of securenets was added for V4.0 (see the ypserv and
ypxfrd man pages).

I don't work for the security group, and can't help you with
an "official" statement.

Mike
8844.2REF: note 2211.3 for helpBSS::BORENMon Feb 17 1997 09:2713
    
    
    re: .0

    
    see note 2211.3 to get connected helping address these types of issues,
    posting to this (or any notesfile) may not get the help you seek.
    
    talkd - Digital's response is in the advisory noted. (in progress)
    nis -   it's still being worked.
    				regards
                        		rich boren
    			
8844.3MUNICH::CUZUMThu Jun 05 1997 09:298
    Hi,
    
    anything new about the talkd-security hole?
    
    Regards,
    
    Corina
    
8844.4SMURF::MAJESKEThu Jun 05 1997 15:287
    I think that the patch is available.  To find out for sure, or
    to get the "official" answer you can try contacting Henry Bone
    ([email protected]) who I understand is the UNIX support (USEG) contact
    for security related issues, or you can try contacting the SSRT 
    directly (Rich Boren, BSS::BOREN).  SSRT is the Corporate Security
    group responsible for coordinating the reporting and resolution of
    security concerns for all products, not just Digital UNIX.