AT&T TCP/IP /usr/etc/rexecd Vulnerability
BID:36
Info
AT&T TCP/IP /usr/etc/rexecd Vulnerability
| Bugtraq ID: | 36 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 1992 12:00AM |
| Updated: | Feb 25 1992 12:00AM |
| Credit: | |
| Vulnerable: |
AT&T TCP/IP 4.0 |
| Not Vulnerable: |
AT&T TCP/IP 3.2 AT&T SVR4 4.0 |
Discussion
AT&T TCP/IP /usr/etc/rexecd Vulnerability
A vulnerability has been identified in AT&T TCP/IP Release
4.0 running on SVR4 systems for both the 386/486 and
3B2 RISC platforms where root privileges may be accessed
through the use of /usr/etc/rexecd.
A user on a remote machine may be able to run commands
as root on the target host (the host running the affected
/usr/etc/rexecd).
The problem does not exist in TCP/IP release 3.2 for SVR3,
or any earlier versions of the TCP/IP product running on
either the 3B2 or 386 platforms.
The version of TCP/IP distributed with SVR4 by UNIX(r)
System Laboratories, Inc. (a subsidiary of AT&T) does not
contain this vulnerability.
A vulnerability has been identified in AT&T TCP/IP Release
4.0 running on SVR4 systems for both the 386/486 and
3B2 RISC platforms where root privileges may be accessed
through the use of /usr/etc/rexecd.
A user on a remote machine may be able to run commands
as root on the target host (the host running the affected
/usr/etc/rexecd).
The problem does not exist in TCP/IP release 3.2 for SVR3,
or any earlier versions of the TCP/IP product running on
either the 3B2 or 386 platforms.
The version of TCP/IP distributed with SVR4 by UNIX(r)
System Laboratories, Inc. (a subsidiary of AT&T) does not
contain this vulnerability.
Exploit / POC
AT&T TCP/IP /usr/etc/rexecd Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AT&T TCP/IP /usr/etc/rexecd Vulnerability
Solution:
Administrators of affected systems should execute, as root, the
following command to immediately turn off access to rexecd until
the new binary can be obtained.
# chmod 400 /usr/etc/rexecd
A new executable for rexecd is available from AT&T by
calling 800-543-9935. Patches may be obtained outside
the U.S. by calling your local technical support. The
numbers associated with the fix are 5127 (3.5" media) and
5128 (5.25" media).
Solution:
Administrators of affected systems should execute, as root, the
following command to immediately turn off access to rexecd until
the new binary can be obtained.
# chmod 400 /usr/etc/rexecd
A new executable for rexecd is available from AT&T by
calling 800-543-9935. Patches may be obtained outside
the U.S. by calling your local technical support. The
numbers associated with the fix are 5127 (3.5" media) and
5128 (5.25" media).