rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2683-1
New dev, rxvt, and screen packages are available that fix a security issue with the packages that originally shipped with Red Hat Linux 6.0. Please read the 'Solution' section for special action needed to complete this upgrade. red hat corp/contact.html . Red Hat, Inc. Security Advisory Package dev, rxvt, screen Synopsis New dev, rxvt, screen packages for Red Hat Linux 6.0 Advisory ID RHSA-1999:014-01 Issue Date 1999-06-15 Keywords dev rxvt screen pts devpts tty 1. Topic: New dev, rxvt, and screen packages are available that fix a security issue with the packages that originally shipped with Red Hat Linux 6.0. Please read the 'Solution' section for special action needed to complete this upgrade. 2. Bug IDs fixed: 2611 3025 3324 3. Relevant releases/architectures: Red Hat Linux 6.0, all architectures 4. Obsoleted by: None 5. Conflicts with: None 6. RPMs required: Intel: dev-2.7.7- 2.i386.rpm rxvt-2.6.0- 2.i386.rpm screen- 3.7.6-9.i386.rpm Alpha: dev-2.7.7- 2.alpha.rpm rxvt-2.6.0- 2.alpha.rpm screen- 3.7.6-9.alpha.rpm SPARC: dev-2.7.7- 2.sparc.rpm rxvt-2.6.0- 2.sparc.rpm screen- 3.7.6-9.sparc.rpm 7. Problem description: The /dev/pts filesystem was mounted with options 'mode=0622' in Red Hat Linux 6.0, instead of the correct 'gid=5,mode=0620'. This could lead to users being able to write to affected ttys. Additionally, once this was corrected, screen and rxvt would still chmod the tty devices to potentially insecure modes. 8. Solution: Upgrade to the latest errata releases of dev, screen and rxvt for Red Hat Linux 6.0 on your particular platform. While the post-install script for the dev package will add the correct permissions for the /dev/pts file system in the /etc/fstab file, you will have to manually unmount and remount the /dev/pts filesystem with the following commands, once the correct permissions have been set in the /etc/fstab file: umount /dev/pts mount /dev/pts If you get the error message "umount: /dev/pts: device is busy" when trying to unmount the filesystem, you will have to close all connections using the filesystem, such as screen, xterm (and other such X terminal programs), and some remote connections. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 34c8c9f6ae3bcb74e63fd67bb785b560 dev-2.7.7-2.i386.rpm 3f0ad6893bdbde6dc9c1a357e555a13b rxvt-2.6.0-2.i386.rpm fc48d9c63ebe02b0fa1741f468f4ccea screen-3.7.6-9.i386.rpm 06777bc610b46490de200cd066c5687b dev-2.7.7-2.alpha.rpm 67bc34923cd2b2a4504fcb14ed735bf8 rxvt-2.6.0-2.alpha.rpm f3c2f2c5867d3bca4a5751fcc8652105 screen-3.7.6-9.alpha.rpm e43914909f7151ef525a6f4b9b1ad461 dev-2.7.7-2.sparc.rpm fe677d3c7d188e204162d4694739639b rxvt-2.6.0-2.sparc.rpm 8e793294d01c9a8f7ded1c563cb0ab92 screen-3.7.6-9.sparc.rpm b25e4de59a00270bb6acd85c8dc901ad dev-2.7.7-2.src.rpm eed32f9b8d67c58d62989758beb7320d rxvt-2.6.0-2.src.rpm f6b51e57e68c9f1e32dd58ef45c76797 screen-3.7.6-9.src.rpm These packages are also PGP signed by Red Hat Inc. for security. Our key is available at: red hat corp/contact.html 10. References: . Bolster system protection through the advancement of secure-shell, terminator, and multiplex packages within Red Hat Linux 6.0 to mitigate potential access risks.. Red Hat Packages, Security Advisory, Linux Updates, Access Control, Linux Compliance. . Severity: Critical. LinuxSecurity.com Team
New rxvt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] rxvt (SSA:2017-121-01) New rxvt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/rxvt-2.7.10-i586-5_slack14.2.txz: Rebuilt. Patched an integer overflow that can crash rxvt with an escape sequence, or possibly have unspecified other impact. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-7483 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/rxvt-2.7.10-i486-5_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/rxvt-2.7.10-x86_64-5_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/rxvt-2.7.10-i486-5_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/rxvt-2.7.10-x86_64-5_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/rxvt-2.7.10-i486-5_slack13.37.txz Updated package for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/rxvt-2.7.10-x86_64-5_slack13.37.txz Updated package for Slackware14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/rxvt-2.7.10-i486-5_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/rxvt-2.7.10-x86_64-5_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/rxvt-2.7.10-i486-5_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/rxvt-2.7.10-x86_64-5_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/rxvt-2.7.10-i586-5_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/rxvt-2.7.10-x86_64-5_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: a15c10264ce5765477432de13579b48f rxvt-2.7.10-i486-5_slack13.0.txz Slackware x86_64 13.0 package: f55562b1a1d6fdc15a9a4f2890238f1d rxvt-2.7.10-x86_64-5_slack13.0.txz Slackware 13.1 package: db90840841f04887dabc377259cd36fb rxvt-2.7.10-i486-5_slack13.1.txz Slackware x86_64 13.1 package: 825608858631aa0be24a1f42a1d9b70d rxvt-2.7.10-x86_64-5_slack13.1.txz Slackware 13.37 package: 4b047b92b11a2cd26b6128c14fa56702 rxvt-2.7.10-i486-5_slack13.37.txz Slackware x86_64 13.37 package: f19b7075fbb0e0bbab9f0856307c2735 rxvt-2.7.10-x86_64-5_slack13.37.txz Slackware 14.0 package: 3f1eac3d0b82ae20f291558899970c02 rxvt-2.7.10-i486-5_slack14.0.txz Slackware x86_64 14.0 package: 807e723ab1e3e339570f30a56c81809c rxvt-2.7.10-x86_64-5_slack14.0.txz Slackware 14.1 package: b08b3976772f322e34c37241efa0d92c rxvt-2.7.10-i486-5_slack14.1.txz Slackware x86_64 14.1 package: 883a5e61212c9bd6a501eaa2f26cc537 rxvt-2.7.10-x86_64-5_slack14.1.txz Slackware 14.2 package: 9c911a2d3ce544504001a6126f05ed1e rxvt-2.7.10-i586-5_slack14.2.txz Slackware x86_6414.2 package: 259ddfb7572a413baacc281e951bba9b rxvt-2.7.10-x86_64-5_slack14.2.txz Slackware -current package: 762750b7b19257fa85a5b333ea3ce4af xap/rxvt-2.7.10-i586-5.txz Slackware x86_64 -current package: 1fb40762cda1489ecb04798184d941ed xap/rxvt-2.7.10-x86_64-5.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg rxvt-2.7.10-i586-5_slack14.2.txz +-----+ . Latest rxvt updates have been released for various Slackware editions to tackle a serious integer overflow vulnerability.. Rxvt Security, Slackware Update, Integer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
There are multiple vulnerabilites in rxvt.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-16 - - --------------------------------------------------------------------- PACKAGE : rxvt SUMMARY : dangerous interception of escape sequences DATE : 2003-03-20 09:57 UTC EXPLOIT : remote VERSIONS AFFECTED : =2.7.8-r6 CVE : CAN-2003-0021 CAN-2003-0068 - - --------------------------------------------------------------------- - From advisory: "Many of the features supported by popular terminal emulator software can be abused when un-trusted data is displayed on the screen. The impact of this abuse can range from annoying screen garbage to a complete system compromise. All of the issues below are actually documented features, anyone who takes the time to read over the man pages or source code could use them to carry out an attack." Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running x11-terms/rxvt upgrade to rxvt-2.7.8-r6 as follows: emerge sync emerge rxvt emerge clean - - ---------------------------------------------------------------------
Updated rxvt packages are available which fix a number of vulnerabilities in the handling of escape sequences.. ` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated rxvt packages fix various vulnerabilites Advisory ID: RHSA-2003:054-00 Issue date: 2003-03-17 Updated on: 2003-03-17 Product: Red Hat Linux Keywords: trojan escape reporting Cross references: Obsoletes: CVE Names: CAN-2003-0022 CAN-2003-0023 CAN-2003-0066 --------------------------------------------------------------------- 1. Topic: Updated rxvt packages are available which fix a number of vulnerabilities in the handling of escape sequences. 2. Relevant releases/architectures: Red Hat Linux 6.2 - i386 Red Hat Linux 7.0 - i386 Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 3. Problem description: Rxvt is a color VT102 terminal emulator for the X Window System. A number of issues have been found in the escape sequence handling of Rxvt. These could be potentially exploited if an attacker can cause carefully crafted escape sequences to be displayed on a rxvt terminal being used by their victim. One of the features which most terminal emulators support is the ability for the shell to set the title of the window using an escape sequence. Certain xterm variants, including rxvt, also provide an escape sequence for reporting the current window title. This essentially takes the current title and places it directly on the command line. Since it is not possible to embed a carriage return into the window title itself, the attacker would have to convince the victim to hit enter for it to process the title as a command, although the attacker can perform a number of actions to increase the likelyhood of this happening. The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to auser's terminal, e.g. when the user views a file containing the malicious sequence. The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu. Users of Rxvt are advised to upgrade to these errata packages which contain a patch to disable the title reporting functionality and patches to correct the other issues. Red Hat would like to thank H D Moore for bringing these issues to our attention. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 6.2: SRPMS: i386: Red Hat Linux 7.0: SRPMS: i386: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 356e4148537e1e522cdcbedfb735ef80 6.2/en/os/SRPMS/rxvt-2.7.8-3.6.2.1.src.rpm 8ce644f8e66b473ef91ea5baa70066ea 6.2/en/os/i386/rxvt-2.7.8-3.6.2.1.i386.rpm 08bc3ef32e1bc77836dc266af8ef2fa1 7.0/en/os/SRPMS/rxvt-2.7.8-3.7.0.1.src.rpm b93bc19a8403c72943b33779b44b28fe7.0/en/os/i386/rxvt-2.7.8-3.7.0.1.i386.rpm cf99378c595e06eed1ff0c2a493d0472 7.1/en/os/SRPMS/rxvt-2.7.8-3.7.1.1.src.rpm f973a30d1f45f561a1e15d4c58615526 7.1/en/os/i386/rxvt-2.7.8-3.7.1.1.i386.rpm f5b4712eeb3c941b9b5f2cf3ab6d6dc4 7.2/en/os/SRPMS/rxvt-2.7.8-4.src.rpm 94a3cbbf0dbd8739e9b1b2cc716a326e 7.2/en/os/i386/rxvt-2.7.8-4.i386.rpm 781b84624dda1114d74d09814438c54a 7.2/en/os/ia64/rxvt-2.7.8-4.ia64.rpm f5b4712eeb3c941b9b5f2cf3ab6d6dc4 7.3/en/os/SRPMS/rxvt-2.7.8-4.src.rpm 94a3cbbf0dbd8739e9b1b2cc716a326e 7.3/en/os/i386/rxvt-2.7.8-4.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at About You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920 CVE -CVE-2003-0022 CVE -CVE-2003-0023 CVE -CVE-2003-0066 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: `. A security notice concerning recent rxvt updates rectifying various escape sequence vulnerabilities in Red Hat Linux.. Red Hat Linux, Rxvt Terminal Update, Escape Sequence Fix. . Severity: Critical. LinuxSecurity.com Team
Since rxvt is installed sgid utmp an attacker could use thisto gain utmp which would allow him to modify the utmp file.. ------------------------------------------------------------------------ Debian Security Advisory DSA-062-1
Get the latest Linux and open source security news straight to your inbox.