Ultrix DECnet-Internet gateway Vulnerability
BID:30
Info
Ultrix DECnet-Internet gateway Vulnerability
| Bugtraq ID: | 30 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 26 1991 12:00AM |
| Updated: | Sep 26 1991 12:00AM |
| Credit: | |
| Vulnerable: |
Digital Ultrix 4.2 Digital Ultrix 4.1 Digital Ultrix 4.0 |
| Not Vulnerable: | |
Discussion
Ultrix DECnet-Internet gateway Vulnerability
When installing the DECnet-Internet gateway software it is
necessary to create a guest account on the ULTRIX gateway
host. By default, this account has /bin/csh as its shell. By
virtue of the guest account having a valid shell, the
DECnet-Internet gateway software can be exploited to
allow unauthorized root access.
Anyone using the DECnet-Internet gateway can gain
unauthorized root privileges on the ULTRIX gateway host.
When installing the DECnet-Internet gateway software it is
necessary to create a guest account on the ULTRIX gateway
host. By default, this account has /bin/csh as its shell. By
virtue of the guest account having a valid shell, the
DECnet-Internet gateway software can be exploited to
allow unauthorized root access.
Anyone using the DECnet-Internet gateway can gain
unauthorized root privileges on the ULTRIX gateway host.
Solution / Fix
Ultrix DECnet-Internet gateway Vulnerability
References
Ultrix DECnet-Internet gateway Vulnerability
References:
References: