Originally Published: Sunday, 20 February 2000 Author: Derrick H. Lewis
Published to: news_enhance_security/Security News Page: 1/1 - [Printable]

TurboLinux Security Announcement

A security hole was discovered in the package mentioned above. Please update the package in your installation as soon as possible or disable the service.

   Page 1 of 1  

Advisories: TurboLinux 2/18/2000 19:47 ______________________________________________________________________________

TurboLinux Security Announcement

Package: gdm-2.0beta4-12 and earlier Date: Thu Feb 17 15:46:26 PST 2000 Affected TurboLinux versions: 6.0 Vulnerability Type: local root password brute force TurboLinux Advisory ID#: TLSA2000001-01 Credits: Michael Warfield of Internet Security Systems, Inc. ______________________________________________________________________________

A security hole was discovered in the package mentioned above. Please update the package in your installation as soon as possible or disable the service. _____________________________________________________________________________ 1. Problem Summary Gdmlogin was configured to give verbose, specific authenication failure messages. This provides (1)verification of user accounts on a machine configured to use the graphical login method to any person, without them ever having to log into the system, and (2)if the username they are trying is root, it lets them know if the password they supplied is incorrect. 2. Impact

A malicious local user could easily find a valid user account name on the machine. This security hole makes for simple password cracking attempts via brute force. If the password being cracked is that of the root user, this can lead to a local root compromise.

3. Solution

Update the package from our ftp server by running the following command: rpm -Uv ftp_path_to_filename

Where ftp_path_to_filename is the following:

ftp://ftp.turbolinux.com/pub/updates/6.0/security/gdm-2.0beta4-13.i386.rpm

Then, restart gdm with the following command:

/usr/bin/gdm restart ______________________________________________________________________________ You can find more updates on our ftp server:

ftp://ftp.turbolinux.com/pub/updates/6.0/security/ for TL6.0 Workstation and Server security updates ftp://ftp.turbolinux.com/pub/updates/4.0/security/ for TL4.0 Workstation and Server security updates

Our webpage for security announcements:

http://www.turbolinux.com/security

If you want to report vulnerabilities, please contact:

security-rt@turbolinux.com ______________________________________________________________________________

Subscribe or Unsubscribe to the TurboLinux Security Mailing lists:

TL-security - A moderated list for discussing security issues in TurboLinux products. Subscribe at http://www.turbolinux.com/mailman/listinfo/tl-security

TL-security-announce - An announce-only mailing list for security updates and alerts. Subscribe at http://www.turbolinux.com/mailman/listinfo/tl-security-announce

** Please do not reply to this email. This is a read-only list. If you wish to change your subscription (set options like digest and delivery modes, get a reminder of your password, or unsubscribe from the list), go to the url supplied above. ** ______________________________________________________________________________





   Page 1 of 1