AUSCERT External Security Bulletin Redistribution

                   ESB-2001.157 -- SGI Security Advisory
                         IRIX BIND Vulnerabilities
                               19 April 2001


        AusCERT Security Bulletin Summary

Product:                BIND
Vendor:                 ISC
Operating System:       IRIX
Impact:                 Root Compromise
Access Required:        Remote

Ref:                    AA-2001.01

- --------------------------BEGIN INCLUDED TEXT--------------------


                          SGI Security Advisory

        Title:      IRIX BIND Vulnerabilities
        Number:     20010401-01-P
        Date:       April 18, 2001
        Reference:  CERT® Advisory CA-2001-02 Multiple Vulnerabilities in BIND
        Reference:  CERT® Incident Note IN-2001-03
        Reference:  CVE CAN-2001-0011, CAN-2001-0012, CAN-2001-0013

- - -----------------------
- - --- Issue Specifics ---
- - -----------------------

The BIND distribution provides Internet domain name service known as DNS.

CERT has reported several vulnerabilities that have been discovered in
the BIND named daemon.

SGI has investigated the issue and provides the following information for
customer interpretation and possible action.

- - --------------
- - --- Impact ---
- - --------------

SGI distributes BIND 4.9.7 on IRIX as eoe.sw.named which is not loaded
by default on IRIX systems.

SGI distributes BIND 8.2.2 on Freeware CDs and on the Freeware website:

A local user account on a vulnerable DNS server is not required in order
to exploit named daemon.

The named daemon can be exploited remotely over an untrusted network.

The named daemon vulnerabilities can lead to a root compromise.

The named vulnerabilities were discovered by NAI COVERT Labs:

The named vulnerabilities were reported by CERT® Coordination Center:

The CVE candidates for these vulnerabilities are:

The BIND vulnerabilities have been publicly discussed in USENET newsgroups
and security mailing lists:

- - --------------------------
- - --- Temporary Solution ---
- - --------------------------

Unfortunately, there are no immediate or temporary workarounds for
this issue.  This issue can only be addressed with the installation
of a patch, installation of the overlay 12 for IRIX 6.5 (IRIX 6.5.12), or
installation of BIND 4.9.8 or BIND 8.2.3 from http://www.isc.org/

The steps below can be used to disable the named daemon to prevent
exploitation of this vulnerability until patches can be installed.

     1) Become the root user on the system.

                % /bin/su -

     2) Check to see if the system is running the named daemon.

                # chkconfig

                Flag                 State
                ====                 =====
                named                off

        If named is disabled, then the system is not vulnerable
        to these BIND vulnerabilities.

     3) Disable named daemon.

                # chkconfig named off

     4) Kill any running named daemons.

                # /sbin/killall named

     5) Return to previous level.

                # exit

     6) Install patches when possible.

- - ----------------
- - --- Solution ---
- - ----------------

Install IRIX 6.5.12 when available or patch 4193 for IRIX 6.5-6.5.11

   OS Version     Vulnerable?     Patch #      Other Actions
   ----------     -----------     -------      -------------

   IRIX 3.x         unknown                    Note 1
   IRIX 4.x         unknown                    Note 1
   IRIX 5.X         unknown                    Note 1
   IRIX 6.0.x       unknown                    Note 1
   IRIX 6.1         unknown                    Note 1
   IRIX 6.2         unknown                    Note 1
   IRIX 6.3         unknown                    Note 1
   IRIX 6.4         unknown                    Note 1
   IRIX 6.5          yes          4193         Note 2
   IRIX 6.5.1        yes          4193         Note 2
   IRIX 6.5.2        yes          4193         Note 2
   IRIX 6.5.3        yes          4193         Note 2
   IRIX 6.5.4        yes          4193         Note 2
   IRIX 6.5.5        yes          4193         Note 2
   IRIX 6.5.6        yes          4193         Note 2
   IRIX 6.5.7        yes          4193         Note 2
   IRIX 6.5.8        yes          4193         Note 2
   IRIX 6.5.9        yes          4193         Note 2
   IRIX 6.5.10       yes          4193         Note 2
   IRIX 6.5.11       yes          4193         Note 3 & 4
   IRIX 6.5.12       no                        Note 5


     1) This version of the IRIX operating has been retired.
        Upgrade to an actively supported IRIX operating system.
        See http://support.sgi.com/news/support/index.html#support_policy
        for more information.

     2) This version of the IRIX operating system is in maintenance mode.
        Upgrade to an actively supported IRIX operating system.
        See http://support.sgi.com/news/support/index.html#support_policy
        for more information.

     3) If you have not received an Overlay 11 CD for IRIX 6.5, contact your
        SGI Support Provider or URL: http://support.sgi.com/irix/swupdates/

     4) Download the IRIX 6.5.11 Maintenance Release Stream from the URL:

     5) IRIX 6.5.12 Maintenance Release Stream is scheduled to be
        released in May 2001

Patches are available via the web, anonymous FTP and from your SGI
service/support provider.

SGI patches for IRIX can be found at the following patch servers:
http://support.sgi.com/irix/ and ftp://patches.sgi.com/

SGI Security Patches can be found at:
http://www.sgi.com/support/security/ and

SGI Security Advisories can be found at:
http://www.sgi.com/support/security/ and

SGI freeware updates for IRIX can be found at:

SGI fixes for SGI open sourced code can be found on:

SGI patches and RPMs for Linux can be found at:
http://support.sgi.com/linux/ or

SGI patches for Windows NT or 2000 can be found at:

IRIX 5.2-6.4 Recommended/Required Patch Sets can be found at:
http://support.sgi.com/irix/ and ftp://patches.sgi.com/support/patchset/

IRIX 6.5 Maintenance Release Streams can be found at:

IRIX 6.5 Software Update CDs can be obtained from:

The primary SGI anonymous FTP site for security advisories and patches
is patches.sgi.com (  Security advisories and patches
are located under the URL ftp://patches.sgi.com/support/free/security/

For security and patch management reasons, ftp.sgi.com (mirrors
patches.sgi.com security FTP repository) lags behind and does not
do a real-time update.

                 ##### Patch File Checksums ####

The actual patch will be a tar file containing the following files:

Filename:                 README.patch.4193
Algorithm #1 (sum -r):    01206 8 README.patch.4193
Algorithm #2 (sum):       48388 8 README.patch.4193
MD5 checksum:

Filename:                 patchSG0004193
Algorithm #1 (sum -r):    25396 3 patchSG0004193
Algorithm #2 (sum):       52827 3 patchSG0004193
MD5 checksum:

Filename:                 patchSG0004193.eoe_sw
Algorithm #1 (sum -r):    56669 318 patchSG0004193.eoe_sw
Algorithm #2 (sum):       44729 318 patchSG0004193.eoe_sw
MD5 checksum:

Filename:                 patchSG0004193.idb
Algorithm #1 (sum -r):    29074 2 patchSG0004193.idb
Algorithm #2 (sum):       43255 2 patchSG0004193.idb
MD5 checksum:

- - ------------------------
- - --- Acknowledgments ----
- - ------------------------

SGI wishes to thank the CERT Coordination Center, NAI COVERT Labs and the
users of the Internet Community at large for their assistance in this matter.

- - -----------------------------------------
- - --- SGI Security Information/Contacts ---
- - -----------------------------------------

If there are questions about this document, email can be sent to


SGI provides security information and patches for use by the entire SGI
community.  This information is freely available to any person needing
the information and is available via anonymous FTP and the Web.

The primary SGI anonymous FTP site for security advisories and patches
is patches.sgi.com (  Security advisories and patches
are located under the URL ftp://patches.sgi.com/support/free/security/

The SGI Security Headquarters Web page is accessible at the URL:

For issues with the patches on the FTP sites, email can be sent to

For assistance obtaining or working with security patches, please
contact your SGI support provider.


SGI provides a free security mailing list service called wiretap and
encourages interested parties to self-subscribe to receive (via email) all
SGI Security Advisories when they are released. Subscribing to the mailing
list can be done via the Web (http://www.sgi.com/support/security/wiretap.html)
or by sending email to SGI as outlined below.

% mail wiretap-request@sgi.com
subscribe wiretap <YourEmailAddress>

In the example above, <YourEmailAddress> is the email address that you
wish the mailing list information sent to.  The word end must be on a
separate line to indicate the end of the body of the message. The
control-d (^d) is used to indicate to the mail program that you are
finished composing the mail message.


SGI provides a comprehensive customer World Wide Web site. This site is
located at http://www.sgi.com/support/security/ .


For reporting *NEW* SGI security issues, email can be sent to
security-alert@sgi.com or contact your SGI support provider.  A
support contract is not required for submitting a security report.

      This information is provided freely to all interested parties
      and may be redistributed provided that it is not altered in any
      way, SGI is appropriately credited and the document retains and
      includes its valid PGP signature.

- --------------------------END INCLUDED TEXT--------------------

This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content.  The decision to use any or all of this information is
the responsibility of each user or organisation, and should be done so in
accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the original authors to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:


If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.

