dbTalk Databases Forums  

Security Vulnerability Alert - February 26, 2010

comp.databases.ingres comp.databases.ingres


Discuss Security Vulnerability Alert - February 26, 2010 in the comp.databases.ingres forum.



Reply
 
Thread Tools Display Modes
  #1  
Old   
Pamela Fowler
 
Posts: n/a

Default Security Vulnerability Alert - February 26, 2010 - 02-26-2010 , 05:11 PM






Dear Valued Ingres Customer:

Information security is of utmost priority to Ingres. A new
vulnerability has recently been identified in Ingres 9.1, Ingres 9.2,
and Ingres 9.3. We have given this vulnerability a security threat
level of ‘Medium’ and recommend that the available security patches be
applied as soon as possible.

Fixes are available for the current release of Ingres 9.1, 9.2, and
9.3 versions on their respective platforms. The security fixes can
be quickly applied with little to no anticipated impact to systems.

Ingres customers with a current support subscription should contact
Ingres Technical Support to obtain the latest patch.

We would like to additionally thank Intevydis Blog for bringing the
following vulnerability to our attention.

Ingres remote user attack after SIGSEGV – bug 123208.
Description: A remote user can send specific data to the DBMS which
triggers a SIGSEGV in memcpy() allowing a remote user to initiate a
Denial of Service (DoS) attack.

For more information about Ingres security alerts and to register to
proactively receive these alerts via email please register at:
http://www.ingres.com/support/securi...ouncements.php.

Regards,


Bill Maimone Pamela Fowler
Senior Vice President, Engineering VP of Worldwide Support/Security
Vulnerabilities
Ingres Corporation Ingres Corporation

Reply With Quote
  #2  
Old   
Ingres Forums
 
Posts: n/a

Default Re: Security Vulnerability Alert - February 26, 2010 - 03-10-2010 , 01:15 AM






I checked the latest patch for 9.2 which is 13711. It makes no mention
of a fix for this bug.

Is a security fix different from a normal patch ?

The knowledge document says that this problem has been resolved in the
current 9.2 codelines. What does that mean ?

If a remote user can send the data and cause the crash, does that mean
that an internal user can do it as well ?


--
adilia.murabito (AT) nrm (DOT) qld.gov.au
------------------------------------------------------------------------
adilia.murabito (AT) nrm (DOT) qld.gov.au's Profile: http://community.ingres.com/forum/me...hp?userid=3009
View this thread: http://community.ingres.com/forum/sh...ad.php?t=11706

Reply With Quote
  #3  
Old   
Ingres Forums
 
Posts: n/a

Default Re: Security Vulnerability Alert - February 26, 2010 - 03-10-2010 , 01:43 AM



I can see bug 123208 listed in the patch.html delivered with patch
13711, and the readme on ESD. This bug number is the one referred to in
the Security Vulnerability notice.

Patch 13711 contains the fix you need.


--
denjo02

Reply With Quote
  #4  
Old   
Ingres Forums
 
Posts: n/a

Default Re: Security Vulnerability Alert - February 26, 2010 - 03-10-2010 , 06:51 PM



Thanks for your reply. I can see the bug now too. My mistake.

I am still wondering, if a remote user can send the data and cause the
crash, does that mean that an internal user can do it as well ? I might
just raise a call with the service desk to find out.


--
adilia.murabito (AT) nrm (DOT) qld.gov.au
------------------------------------------------------------------------
adilia.murabito (AT) nrm (DOT) qld.gov.au's Profile: http://community.ingres.com/forum/me...hp?userid=3009
View this thread: http://community.ingres.com/forum/sh...ad.php?t=11706

Reply With Quote
  #5  
Old   
Kristoff
 
Posts: n/a

Default Re: Security Vulnerability Alert - February 26, 2010 - 03-11-2010 , 02:53 AM



On Mar 11, 1:51*am, Ingres Forums <info-
ing... (AT) kettleriverconsulting (DOT) com> wrote:
Quote:
Thanks for your reply. *I can see the bug now too. *My mistake.

I am still wondering, if a remote user can send the data and cause the
crash, does that mean that an internal user can do it as well ? I might
just raise a call with the service desk to find out.

--
adilia.murab... (AT) nrm (DOT) qld.gov.au
------------------------------------------------------------------------
adilia.murab... (AT) nrm (DOT) qld.gov.au's Profile:http://community.ingres.com/forum/me...hp?userid=3009
View this thread:http://community.ingres.com/forum/sh...ad.php?t=11706
Yes, an internal user can do that too. For remote users there is a
workaround, either use Unix sockets (II_GC_PROT) or use a firewall to
prevent any access to "unusual" ports.(meaning give access to the
needed ports only for ssh, telnet or whatever).
But you can not block the DBMS port for internal users ......

Please note, that this problem exists on Unix/Linux only, no need to
worry when using Windows (relating to this problem of course) or VMS

Kristoff

Reply With Quote
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.