RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
BID:28383
Info
RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 28383 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 21 2008 12:00AM |
| Updated: | Mar 22 2008 01:20AM |
| Credit: | kcope |
| Vulnerable: |
Sun Solaris 10 |
| Not Vulnerable: | |
Discussion
RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
Sun Solaris is prone to an arbitrary command execution vulnerability because it fails to adequately sanitize user-supplied data to 'rpc.ypupdated'.
Attackers can leverage this issue to execute arbitrary commands on vulnerable computers. Successful exploits will compromise the compromise the computer.
This issue occurs only when 'rpc.ypupdated' is started using the '-i' command line switch. This switch is not used by default.
Sun Solaris 10 is vulnerable; other versions may also be affected.
Reports indicate that this issue was originally discovered in 1994.
This BID is being retired as it is a duplicate of the vulnerability discussed in BID 1749 (Multiple Vendor RPC.YPUpdated Command Execution Vulnerability).
Sun Solaris is prone to an arbitrary command execution vulnerability because it fails to adequately sanitize user-supplied data to 'rpc.ypupdated'.
Attackers can leverage this issue to execute arbitrary commands on vulnerable computers. Successful exploits will compromise the compromise the computer.
This issue occurs only when 'rpc.ypupdated' is started using the '-i' command line switch. This switch is not used by default.
Sun Solaris 10 is vulnerable; other versions may also be affected.
Reports indicate that this issue was originally discovered in 1994.
This BID is being retired as it is a duplicate of the vulnerability discussed in BID 1749 (Multiple Vendor RPC.YPUpdated Command Execution Vulnerability).
Exploit / POC
RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
RETIRED: Sun Solaris 'rpc.ypupdated' Arbitrary Command Execution Vulnerability
References:
References:
- Sun Solaris Homepage (Sun Microsystems)