RWhoIsD System Log Format String Vulnerability
BID:3571
Info
RWhoIsD System Log Format String Vulnerability
| Bugtraq ID: | 3571 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2001 12:00AM |
| Updated: | Nov 22 2001 12:00AM |
| Credit: | Posted by alert7 <[email protected]> to the BugTraq mailing list on November 22, 2001. |
| Vulnerable: |
Network Solutions rwhoisd 1.5.7 .1 Network Solutions rwhoisd 1.5.7 Network Solutions rwhoisd 1.5.6 Network Solutions rwhoisd 1.5.5 Network Solutions rwhoisd 1.5.3 Network Solutions rwhoisd 1.5.2 Network Solutions rwhoisd 1.5.1 a Network Solutions rwhoisd 1.5 |
| Not Vulnerable: | |
Discussion
RWhoIsD System Log Format String Vulnerability
Rwhosid is a RWHOIS daemon provided by Network Solutions. RWHOIS is a protocol for remote listing of user name, login time, elapsed time online and other pertinent data for users connected to all machines on a network.
When a remote request is logged through the syslog function, the format string passed contains user supplied input. This may lead to memory corruption, and the execution of arbitrary code by rwhoisd. This will only occur when the option "set use-syslog: YES" is set in the rwhoisd.conf file. This option is enabled by default.
Rwhosid is a RWHOIS daemon provided by Network Solutions. RWHOIS is a protocol for remote listing of user name, login time, elapsed time online and other pertinent data for users connected to all machines on a network.
When a remote request is logged through the syslog function, the format string passed contains user supplied input. This may lead to memory corruption, and the execution of arbitrary code by rwhoisd. This will only occur when the option "set use-syslog: YES" is set in the rwhoisd.conf file. This option is enabled by default.
Exploit / POC
RWhoIsD System Log Format String Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RWhoIsD System Log Format String Vulnerability
Solution:
Remove the line set use-syslog: YES from the rwhoisd.conf file.
Solution:
Remove the line set use-syslog: YES from the rwhoisd.conf file.