From owner-doc-jp@jp.FreeBSD.org Wed Dec 12 01:15:02 2001
Received: (from daemon@localhost)
	by castle2.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) id fBBGF2872687;
	Wed, 12 Dec 2001 01:15:02 +0900 (JST)
	(envelope-from owner-doc-jp@jp.FreeBSD.org)
Received: from castle.jp.freebsd.org (castle.jp.FreeBSD.org [210.226.20.15])
	by castle2.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) with ESMTP/inet id fBBGF2m72682
	for <doc-jp@castle2.jp.freebsd.org>; Wed, 12 Dec 2001 01:15:02 +0900 (JST)
	(envelope-from owner-doc-jp@castle2.jp.freebsd.org)
Received: from eos.ocn.ne.jp (eos.ocn.ne.jp [210.190.142.171])
	by castle.jp.freebsd.org (8.9.3+3.2W/8.7.3) with ESMTP id BAA96823
	for <doc-jp@jp.FreeBSD.org>; Wed, 12 Dec 2001 01:15:02 +0900 (JST)
	(envelope-from hrs@eos.ocn.ne.jp)
Received: from mail.hrslab.yi.org (p5126-ip02funabasi.chiba.ocn.ne.jp [61.214.4.126])
	by eos.ocn.ne.jp (OCN) with ESMTP id BAA18707
	for <doc-jp@jp.FreeBSD.org>; Wed, 12 Dec 2001 01:14:59 +0900 (JST)
Received: from localhost (alph.hrslab.yi.org [192.168.0.10])
	by mail.hrslab.yi.org (8.9.3/3.7W/DomainMaster) with ESMTP id BAA25512
	for <doc-jp@jp.FreeBSD.org>; Wed, 12 Dec 2001 01:09:20 +0900 (JST)
	(envelope-from hrs@eos.ocn.ne.jp)
Date: Wed, 12 Dec 2001 01:07:10 +0900 (JST)
Message-Id: <20011212.010710.08321715.hrs@eos.ocn.ne.jp>
To: doc-jp@jp.FreeBSD.org
From: Hiroki Sato <hrs@eos.ocn.ne.jp>
In-Reply-To: <200112041854.fB4IsI319200@freefall.freebsd.org>
References: <200112041854.fB4IsI319200@freefall.freebsd.org>
X-Mailer: Mew version 2.0 on Emacs 20.7 / Mule 4.0 (HANANOEN)
Mime-Version: 1.0
Content-Type: Multipart/Mixed;
 boundary="--Next_Part(Wed_Dec_12_01:07:10_2001_037)--"
Content-Transfer-Encoding: 7bit
Reply-To: doc-jp@jp.FreeBSD.org
Precedence: list
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+010331
X-Sequence: doc-jp 8551
Subject: [doc-jp 8551] Re: ANNOUNCE: FreeBSD Ports Security Advisory
 FreeBSD-SA-01:64.wu-ftpd
Errors-To: owner-doc-jp@jp.FreeBSD.org
Sender: owner-doc-jp@jp.FreeBSD.org
X-Originator: hrs@eos.ocn.ne.jp

----Next_Part(Wed_Dec_12_01:07:10_2001_037)--
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Transfer-Encoding: 7bit

$B:4F#!wEl5~M}2JBg3X$G$9!#(B

 01:64 $B$G$9!#(B

--
| $B:4F#(B $B9-@8!wEl5~M}2JBg3X(B <hrs@eos.ocn.ne.jp>
|                         <hrs@FreeBSD.org> (FreeBSD Project)

----Next_Part(Wed_Dec_12_01:07:10_2001_037)--
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Disposition: inline; filename="01:64"
Content-Transfer-Encoding: 7bit


FreeBSD $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG(B
=============================================================================
FreeBSD-SA-01:64 (2001-12-04)
 * wu-ftpd port contains remote root compromise
=============================================================================

 $B$3$N%a!<%k$O(B, announce-jp $B$KN.$l$?(B

  Subject: ANNOUNCE: FreeBSD Ports Security Advisory FreeBSD-SA-01:64.wu-ftpd
  From: FreeBSD Security Advisories <security-advisories@freebsd.org>
  Date: Tue, 4 Dec 2001 10:54:18 -0800 (PST)
  Message-Id: <200112041854.fB4IsI319200@freefall.freebsd.org>
  X-Sequence: announce-jp 859

 $B$rF|K\8lLu$7$?$b$N$G$9(B. 

 $B86J8$O(B PGP $B=pL>$5$l$F$$$^$9$,(B, $B$3$NF|K\8lLu$O(B PGP $B=pL>$5$l$F$$$^$;$s(B. 
 $B=$@5%Q%C%AEy$NFbMF$,2~$6$s$5$l$F$$$J$$$3$H$r3NG'$9$k$?$a$K(B PGP $B=pL>$N(B
 $B%A%'%C%/$r9T$J$&$K$O(B, $B86J8$r;2>H$7$F$/$@$5$$(B. 

 $BF|K\8lLu$*$h$S(B, $B%_%i!<%5%$%HMxMQ$N>\:Y$K$D$$$F$O(B, $BJ8Kv$N!V(BA. FreeBSD
 $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG$K$D$$$F!W$r$4Mw$/$@$5$$(B.


                                     [$BK]Lu<T(B: $B:4F#(B $B9-@8(B <hrs@jp.FreeBSD.org>]
--($B$3$3$+$i(B)

=============================================================================
FreeBSD-SA-01:64                                           Security Advisory
                                                                FreeBSD, Inc.

$B%H%T%C%/(B:	wu-ftpd port contains remote root compromise
                wu-ftpd port $B$K$*$1$k%j%b!<%H$+$i$N(B root $B8"8B$NIT@5;HMQLdBj(B

$BJ,N`(B:		ports
$B%b%8%e!<%k(B:	wu-ftpd
$B9pCNF|(B:		2001-12-04
$B%/%l%8%C%H(B:	CORE Security Technologies
                $BO"Mm@h(B: Ivan Arce (iarce@corest.com)
$B1F6AHO0O(B:	$B=$@5F|0JA0$N(B Ports Collection
$B=$@5F|(B:		2001-11-28 10:52:26 UTC
FreeBSD $B$K8GM-$+(B:	NO

I.   $BGX7J(B - Background

wu-ftpd is a popular full-featured FTP server.

wu-ftpd $B$O(B, $BA45!G=$rHw$($??M5$$N$"$k(B FTP $B%5!<%P$G$9(B.


II.  $BLdBj$N>\:Y(B - Problem Description

The wu-ftpd port, versions prior to wu-ftpd-2.6.1_7, contains a
vulnerability which allows FTP users, both anonymous FTP users and
those with valid accounts, to execute arbitrary code as root on
the local machine.  This may be accomplished by inserting invalid
globbing parameters which are incorrectly parsed by the FTP server
into command input.

wu-ftpd port $B$N(B wu-ftpd-2.6.1_7 $B0JA0$N%P!<%8%g%s$K$O(B,
FTP $B%f!<%6$,%m!<%+%k%^%7%s>e$N(B root $B8"8B$GG$0U$N%3!<%I$r(B
$B<B9T$G$-$k4m81@-$r;}$C$?%;%-%e%j%F%#>e$N<eE@$,B8:_$7$^$9(B.
$B$3$N(B FTP $B%f!<%6$K$O(B, anonymous FTP $B%f!<%6$*$h$S(B, $B%"%+%&%s%H$r(B
$B;}$C$?%f!<%6$NN>J}$,4^$^$l$^$9(B.  $B$3$NG$0U$N%3!<%I$N<B9T$O(B,
FTP $B%5!<%P$K$h$C$FITE,@Z$K2r<a$5$l$k$h$&$J(B, $BIT@5$J(B
$B%0%m%V%Q%i%a!<%?$rF~NO%3%^%s%I$KA^F~$9$k$3$H$G<B8=2DG=$G$9(B.

The wu-ftpd port is not installed by default, nor is it "part of
FreeBSD" as such: it is part of the FreeBSD ports collection, which
contains over 6000 third-party applications in a ready-to-install
format. The ports collection shipped with FreeBSD 4.4 contains this
problem since it was discovered after the release.

FreeBSD makes no claim about the security of these third-party
applications, although an effort is underway to provide a security
audit of the most security-critical ports.

procmail $B$N(B port $B$O%G%U%)%k%H$G%$%s%9%H!<%k$5$l$k$b$N$G$O$J$/(B,
$B!V(BFreeBSD $B%7%9%F%`$N0lIt!W$r9=@.$9$k$b$N$G$b$"$j$^$;$s(B.
$B$=$l$i$O(B 6000 $B$r1[$($k%5!<%I%Q!<%F%#@=%"%W%j%1!<%7%g%s$,$9$0$K(B
$B%$%s%9%H!<%k$G$-$k7A$G<}$a$i$l$F$$$k(B FreeBSD Ports Collection $B$N0lIt$G$9(B.
$B$3$NLdBj$O(B FreeBSD 4.4 $B$N%j%j!<%98e$KH/8+!&=$@5$5$l$?$?$a(B, FreeBSD 4.4 $B$K$O(B
$B$3$NLdBj$K$h$k%;%-%e%j%F%#>e$N<eE@$,4^$^$l$F$$$^$9(B.

FreeBSD $B$G$O(B, $B$3$N$h$&$J%5!<%I%Q!<%F%#@=%"%W%j%1!<%7%g%s$N%;%-%e%j%F%#(B
$BLdBj$KBP$7$F(B, $BFC$K2?$+$r<gD%$9$k$3$H$O$"$j$^$;$s(B ($BLuCm(B: Ports Collection $B$K(B
$BF~$C$F$$$k$+$i$H$$$C$F(B, FreeBSD $B$N3+H/<T$?$A$,$=$N%"%W%j%1!<%7%g%s$,(B
$B0BA4$G$"$k$HI>2A$7$?$o$1$G$O$"$j$^$;$s(B).  $B$?$@$7(B, $B%;%-%e%j%F%#LdBj$KBP$7$F(B
$BBg$-$J1F6A$r;}$D$h$&$J(B ports $B$KBP$9$k%;%-%e%j%F%#4F::$rDs6!$9$Y$/(B,
$B8=:_EXNOCf$G$9(B.


III. $B1F6AHO0O(B - Impact

FTP users, including anonymous FTP users, can cause arbitrary commands
to be executed as root on the local machine.

anonymous FTP $B%f!<%6$r4^$`(B, $B$9$Y$F$N(B FTP $B%f!<%6$O%m!<%+%k%^%7%s>e$N(B
root $B8"8B$GG$0U$N%3!<%I$r<B9T$9$k$3$H$,2DG=$G$9(B.

If you have not chosen to install the wu-ftpd port/package, then your
system is not vulnerable to this problem.

wu-ftpd $B$N(B port/package $B$r%$%s%9%H!<%k$7$F$$$J$1$l$P(B
$B%7%9%F%`$K$3$NLdBj$K$h$k%;%-%e%j%F%#>e$N<eE@$O$"$j$^$;$s(B.


IV.  $B2sHrJ}K!(B - Workaround

Deinstall the wu-ftpd port/package, if you have installed it.

wu-ftpd $B$N(B port/package $B$,%$%s%9%H!<%k$5$l$F$$$k>l9g$O(B,
$B$=$l$r%7%9%F%`$+$i:o=|$7$^$9(B.

V.   $B2r7h:v(B - Solution

$B<!$N$$$:$l$+$K=>$C$F$/$@$5$$(B.

1) Upgrade your entire ports collection and rebuild the wu-ftpd port.
1) Ports Collection $BA4BN$r%"%C%W%0%l!<%I$7(B wu-ftpd $B$N(B port $B$r:F9=C[$9$k(B.

2) Deinstall the old package and install a new package dated after the
correction date, obtained from:
2) $B8E$$(B ($BLuCm(B: wu-ftpd $B$N(B) package $B$r%7%9%F%`$+$i:o=|$7(B,
   $B=$@5F|0J9_$K:n@.$5$l$??7$7$$(B package $B$r0J2<$N>l=j$+$i(B
   $B<hF@$7$F%$%s%9%H!<%k$9$k(B.

[i386]
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/ftp/wu-ftpd-2.6.1_7.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/ftp/wu-ftpd-2.6.1_7.tgz

[alpha]
Packages are not automatically generated for the alpha architecture at
this time due to lack of build resources

$B8=;~E@$G$O(B alpha $B%"!<%-%F%/%A%cMQ$N(B package $B$O<+F0@8@.$5$l$F$$$^$;$s(B.
$B$3$l$O(B, $B9=C[$N$?$a$N%^%7%s%j%=!<%9$,ITB-$7$F$$$k$?$a$G$9(B.

NOTE: It may be several days before updated packages are available. Be
sure to check the file creation date on the package, because the
version number of the software has not changed.

$BCm0U(B: $B99?7$5$l$?(B package $B$,Ds6!$5$l$k$^$G(B, $B?tF|$+$+$k2DG=@-$,$"$j$^$9(B.
      $B$I$A$i$b%=%U%H%&%'%"$N%P!<%8%g%sHV9f$OF10l$G$9$N$G(B,
      package $B%U%!%$%k$N:n@.F|$r3NG'$9$k$h$&$K$7$F$/$@$5$$(B.

3) download a new port skeleton for the wu-ftpd port from:
3) wu-ftpd $B$N?7$7$$(B port $B%9%1%k%H%s$r0J2<$N>l=j$+$i%@%&%s%m!<%I$7(B,
   $B$=$l$r;H$C$F(B port $B$r:F9=C[$9$k(B.

http://www.freebsd.org/ports/

and use it to rebuild the port.

4) Use the portcheckout utility to automate option (3) above. The
portcheckout port is available in /usr/ports/devel/portcheckout or the
package can be obtained from:
4) $B>e5-(B (3) $B$NA`:n$r<+F0E*$K9T$J$&(B portcheckout $B%f!<%F%#%j%F%#$r;H$&(B.
   portcheckout $B$N(B port $B$O(B /usr/ports/devel/portcheckout $B$K$"$j$^$9(B.
   $B$^$?(B, portcheckout $B$N(B package $B$,0J2<$N>l=j$+$iF~<j2DG=$G$9(B.

ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/devel/portcheckout-2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/devel/portcheckout-2.0.tgz


VI.  $B=$@5$N>\:Y(B - Correction details

The following list contains the revision numbers of each file that was
corrected in the FreeBSD ports collection.

$B<!$NI=$O(B, FreeBSD Ports Collection $B$K4^$^$l$F$$$k(B,
$B=$@5$5$l$?%U%!%$%k$=$l$>$l$N%j%S%8%g%sHV9f$G$9(B.

Path                                                             Revision
$B%Q%9L>(B                                                       $B%j%S%8%g%sHV9f(B
- -------------------------------------------------------------------------
ports/ftp/wu-ftpd/Makefile                                         1.41
ports/ftp/wu-ftpd/files/patch-ap                                   1.2
- -------------------------------------------------------------------------


VII. $B;29M;qNA(B - References

<URL:http://www.securityfocus.com/archive/1/242750>


A.   FreeBSD $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG$K$D$$$F(B

$BF|K\8lLu$O(B FreeBSD $BF|K\8l%I%-%e%a%s%F!<%7%g%s%W%m%8%'%/%H(B (doc-jp) $B$,(B
$B;29M$N$?$a$KDs6!$9$k$b$N$G$9(B.  $B2a5n$NF|K\8lHG%;%-%e%j%F%#4+9p$O(B

 http://www.FreeBSD.org/ja/security/

$B$K$^$H$a$i$l$F$$$^$9(B.  

$B$?$@$7(B, $BK]Lu<T$*$h$S(B doc-jp $B$O(B, $B$=$NFbMF$K$D$$$F$$$+$J$kJ]>Z$b(B
$B$$$?$7$^$;$s$N$G$4Cm0U$/$@$5$$(B.  $BF|K\8lLu$K$D$$$F$N$40U8+(B, $B$4MWK>(B,
$B$*Ld$$9g$o$;Ey$O(B doc-jp@jp.FreeBSD.org $B$^$G$*4j$$$7$^$9(B.

$B$3$N4+9p$NCf$G>R2p$5$l$F$$$k(B WWW $B%5%$%H(B http://www.FreeBSD.org/ $B$*$h$S(B
FTP $B%5%$%H(B ftp://ftp.FreeBSD.org/ $B$K$O(B, $BF|K\$N%_%i!<%5%$%H$,B8:_$7$^$9(B.
$B%M%C%H%o!<%/$N:.;($r4KOB$9$k$?$a(B, $B$^$:$O%_%i!<%5%$%H$NMxMQ$r(B
$B9MN8$9$k$h$&$*4j$$$7$^$9(B.

$BF|K\$N%_%i!<%5%$%H$rMxMQ$9$k$K$O(B,
http://www.FreeBSD.org/ $B$r(B http://www.jp.FreeBSD.org/www.freebsd.org/ $B$K(B,
ftp://ftp.FreeBSD.org/ $B$r(B ftp://ftp.jp.FreeBSD.org/ $B$K(B,
$B$=$l$>$lCV$-49$($F$/$@$5$$(B.

$BB>$NCO0h$r4^$`(B, $B%_%i!<%5%$%H$K4X$9$k>\:Y$O(B,

 http://www.FreeBSD.org/handbook/mirror.html ($B1QJ8(B)
 http://www.FreeBSD.org/ja/handbook/mirror.html ($BF|K\8lLu(B)

$B$K$^$H$a$i$l$F$$$^$9(B.

$hrs: announce-jp/FreeBSD-SA/01:64,v 1.1 2001/12/11 15:58:22 hrs Exp $

----Next_Part(Wed_Dec_12_01:07:10_2001_037)----
