| PROBLEM: | Tcpdump is a command-line tool for monitoring network traffic. A compilation error caused tcpdump to run as root rather than dropping to permissions of user 'pcap' as Red Hat previously advertised. |
| PLATFORM: | Red Hat Linux 7.1 Red Hat Linux 7.2 Red Hat Linux 7.3 Red Hat Linux 8.0 Red Hat Linux 9 |
| DAMAGE: | Unnecessarily running programs as root can leave systems vulnerable to many unwanted activities. |
| SOLUTION: | Apply updated packages as stated in Red Hat's bulletin. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Without updating to these new packages, tcpdump would run as root unless the '-U' flag was specified. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/n-097.shtml |
| ORIGINAL BULLETIN: | https://rhn.redhat.com/errata/RHSA-2003-174.html |
[***** Start Red Hat Security Advisory RHSA-2003:174-04 *****]
Updated tcpdump packages fix privilege dropping error
Advisory: RHSA-2003:174-04
Last updated on: 2003-05-15
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
Red Hat Linux 9
CVEs (cve.mitre.org): CAN-2003-0194
Security Advisory
Details:
Updated tcpdump packages that correctly drop privileges on startup are now
available.
Tcpdump is a command-line tool for monitoring network traffic.
The Red Hat tcpdump packages advertise that by default tcpdump will drop
permissions to user 'pcap'. Due to a compilation error this did not
happen, and tcpdump would run as root unless the '-U' flag was specified.
Users of tcpdump are advised to upgrade to these errata packages, which
contain are compiled so that by default tcpdump will drop privileges to the
'pcap' user.
Updated packages:
Red Hat Linux 7.1
--------------------------------------------------------------------------------
SRPMS:
tcpdump-3.6.3-17.7.1.3.src.rpm
[ via FTP ] [ via HTTP ] fac820eb58d79fc58d30bff1fd11f33d
i386:
tcpdump-3.6.3-17.7.1.3.i386.rpm
[ via FTP ] [ via HTTP ] 3eadddac8cdf6ae0b14e8016f651e1f0
Red Hat Linux 7.2
--------------------------------------------------------------------------------
SRPMS:
tcpdump-3.6.3-17.7.2.3.src.rpm
[ via FTP ] [ via HTTP ] 5f5c14bd0dfdaa5b0d5dbc0fb70da395
i386:
tcpdump-3.6.3-17.7.2.3.i386.rpm
[ via FTP ] [ via HTTP ] c48e86db37c7f767ec8931ebb54fc0ae
ia64:
tcpdump-3.6.3-17.7.2.3.ia64.rpm
[ via FTP ] [ via HTTP ] 39da71bfef8520c979db8cf21c4f6781
Red Hat Linux 7.3
--------------------------------------------------------------------------------
SRPMS:
tcpdump-3.6.3-17.7.3.3.src.rpm
[ via FTP ] [ via HTTP ] f9de6824ac351207bd105978eefed89d
i386:
tcpdump-3.6.3-17.7.3.3.i386.rpm
[ via FTP ] [ via HTTP ] 8d54631bf99d61090f0752f29ef51f8f
Red Hat Linux 8.0
--------------------------------------------------------------------------------
SRPMS:
tcpdump-3.6.3-17.8.0.3.src.rpm
[ via FTP ] [ via HTTP ] 67a36a50ec50a8aa2d32b2462fae653d
i386:
tcpdump-3.6.3-17.8.0.3.i386.rpm
[ via FTP ] [ via HTTP ] afba9bea894090b9c179979403347629
Red Hat Linux 9
--------------------------------------------------------------------------------
SRPMS:
tcpdump-3.7.2-1.9.1.src.rpm
[ via FTP ] [ via HTTP ] 1b1b577c9ebfe84f735a6498140e1e7f
i386:
tcpdump-3.7.2-1.9.1.i386.rpm
[ via FTP ] [ via HTTP ] 6cff8bf6b2425c361eec70ba3017d82b
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Bugs fixed: (see bugzilla for more information)
88881 - CAN-2003-0145 RADUIS tcpdump vulnerability
90208 - CAN-2003-0194 tcpdump didn't drop root to pcap user like promised
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0194
Keywords:
tcpdump
--------------------------------------------------------------------------------
The listed packages are GPG signed by Red Hat, Inc. for security. Our key is
available at:
http://www.redhat.com/solutions/security/news/publickey/#key
You can verify each package and see who signed it with the following command:
rpm --checksig -v filename
If you only wish to verify that each package has not been corrupted or tampered
with, examine only the md5sum with the following command:
md5sum filename
The Red Hat security contact is security@redhat.com. More contact details at
http://www.redhat.com/solutions/security/news/contact.html
[***** End Red Hat Security Advisory RHSA-2003:174-04 *****]
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/