Solaris rpcbind Listening on a Non-Standard Port Vulnerability
BID:205
Info
Solaris rpcbind Listening on a Non-Standard Port Vulnerability
| Bugtraq ID: | 205 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 04 1997 12:00AM |
| Updated: | Jun 04 1997 12:00AM |
| Credit: | This bug was originally posted to the Bugtraq mailing list by Secure Networks Inc on June 7, 1997. |
| Vulnerable: |
Wietse Venema Rpcbind Replacement 2.0 Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 |
| Not Vulnerable: |
Wietse Venema Rpcbind Replacement 2.1 Sun Solaris 2.6_x86 Sun Solaris 2.6 SSH Communications Security SSH 1.2.27 FreeBSD FreeBSD 3.3 |
Discussion
Solaris rpcbind Listening on a Non-Standard Port Vulnerability
The rpcbind program that converts RPC program numbers into universal addresses. When a client makes an RPC call to a given program number, it first connects to rpcbind on the target system to determine the address where the RPC request should be sent.Under Solaris 2.x rpcbind not only listens on the TCP / UDP port 111, but it also listens on UDP ports greater than 32770. The exact number is dependent on the OS release and architecture. Thus, packet filtering devices that are configured to block access to rpcbind / portmapper, may be subverted by sending UDP requests to rpcbind listening above port 32770.This vulnerability may allow an unauthorized user to obtain remote RPC information from a remote system even if port 111 is being blocked.
The rpcbind program that converts RPC program numbers into universal addresses. When a client makes an RPC call to a given program number, it first connects to rpcbind on the target system to determine the address where the RPC request should be sent.Under Solaris 2.x rpcbind not only listens on the TCP / UDP port 111, but it also listens on UDP ports greater than 32770. The exact number is dependent on the OS release and architecture. Thus, packet filtering devices that are configured to block access to rpcbind / portmapper, may be subverted by sending UDP requests to rpcbind listening above port 32770.This vulnerability may allow an unauthorized user to obtain remote RPC information from a remote system even if port 111 is being blocked.
References
Solaris rpcbind Listening on a Non-Standard Port Vulnerability
References:
References:
- NAI Security Advisories (Formerly Secure Networks Inc. Advisories) (Network Associates Inc.)
- Sun Patch Access Page (Sun Microsystems)
- Sun Patches List (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)