Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
BID:4044
Info
Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
| Bugtraq ID: | 4044 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Feb 07 2002 12:00AM |
| Credit: | This vulnerability was announced by Caldera on November 15, 2001. |
| Vulnerable: |
SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: |
SCO Open Server 5.0.6 a SCO Open Server 5.0.6 |
Discussion
Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
OpenServer is a commercial UNIX Operating System originally developed by SCO. It is maintained by Caldera.
It is possible to deny users access to services managed by inetd. inetd reacts unpredictably when scanned by a utility such as nmap. One consequence is that nmap crashes inetd, making all services handled by the server unavailable until inetd is manually restarted.
This problem makes it possible to deny service to legitimate users of a system.
OpenServer is a commercial UNIX Operating System originally developed by SCO. It is maintained by Caldera.
It is possible to deny users access to services managed by inetd. inetd reacts unpredictably when scanned by a utility such as nmap. One consequence is that nmap crashes inetd, making all services handled by the server unavailable until inetd is manually restarted.
This problem makes it possible to deny service to legitimate users of a system.
Exploit / POC
Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
This vulnerability may be exploited using nmap.
This vulnerability may be exploited using nmap.
Solution / Fix
Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
Solution:
A vendor fix is available:
SCO Open Server 5.0
SCO Open Server 5.0.1
SCO Open Server 5.0.2
SCO Open Server 5.0.3
SCO Open Server 5.0.4
SCO Open Server 5.0.5
Solution:
A vendor fix is available:
SCO Open Server 5.0
SCO Open Server 5.0.1
SCO Open Server 5.0.2
SCO Open Server 5.0.3
SCO Open Server 5.0.4
SCO Open Server 5.0.5
References
Caldera OpenServer Port Scan InetD Denial of Service Vulnerability
References:
References:
- (Semi ;-) SUMMARY: Setting nmap host_timeout too low may cause DoS on inetd (?) (Alek O. Komarnitsky
)