NeXTstep NetInfo Vulnerability
BID:35
Info
NeXTstep NetInfo Vulnerability
| Bugtraq ID: | 35 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 1992 12:00AM |
| Updated: | Jan 20 1992 12:00AM |
| Credit: | |
| Vulnerable: |
NeXT NeXTstep 2.0 |
| Not Vulnerable: | |
Exploit / POC
NeXTstep NetInfo Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NeXTstep NetInfo Vulnerability
Solution:
Ensure that the trusted_networks property of each NetInfo
domain's root NetInfo directory is set correctly, so that
only those systems which should be obtaining information
from NetInfo are granted access. The value for the
trusted_networks property should be the network numbers
of the networks the server should trust.
Note that improperly setting trusted_networks can render
your network unusable.
Consult Chapter 16, "Security", of the "NeXT Network and
System Administration" manual for release 2 for details on
setting the trusted_networks property of the root NetInfo
directory.
Solution:
Ensure that the trusted_networks property of each NetInfo
domain's root NetInfo directory is set correctly, so that
only those systems which should be obtaining information
from NetInfo are granted access. The value for the
trusted_networks property should be the network numbers
of the networks the server should trust.
Note that improperly setting trusted_networks can render
your network unusable.
Consult Chapter 16, "Security", of the "NeXT Network and
System Administration" manual for release 2 for details on
setting the trusted_networks property of the root NetInfo
directory.
References
NeXTstep NetInfo Vulnerability
References:
References: