AIX rexd Vulnerability
BID:37
Info
AIX rexd Vulnerability
| Bugtraq ID: | 37 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 1992 12:00AM |
| Updated: | Mar 05 1992 12:00AM |
| Credit: | This vulnerability was posted by CERT/CC as CA-92.05 AIX REXD Daemon Vulnerability. |
| Vulnerable: |
IBM AIX 3.2 IBM AIX 3.1 |
| Not Vulnerable: |
IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 3.2.5 IBM AIX 3.2.4 |
Discussion
AIX rexd Vulnerability
In certain configurations, particularly if NFS is installed, the rexd (RPC remote program execution) daemon is enabled.If a system allows rexd connections, anyone on the Internet can gain access to the system as a user other than root.
Note: Installing NFS with the current versions of "mknfs" will re-enable rexd even if it was previously disabled.
In certain configurations, particularly if NFS is installed, the rexd (RPC remote program execution) daemon is enabled.If a system allows rexd connections, anyone on the Internet can gain access to the system as a user other than root.
Note: Installing NFS with the current versions of "mknfs" will re-enable rexd even if it was previously disabled.
Exploit / POC
AIX rexd Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].