Solaris rpc.statd rpc Call Relaying Vulnerability

BID:450

Info

Solaris rpc.statd rpc Call Relaying Vulnerability

Bugtraq ID: 450
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 07 1999 12:00AM
Updated: Jun 07 1999 12:00AM
Credit: First released in Sun Advisory 00186 on June 7, 1999.
Vulnerable: Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Solaris 2.5_x86
Sun Solaris 2.4_x86
Sun Solaris 2.4
Sun Solaris 2.3
Not Vulnerable:

Discussion

Solaris rpc.statd rpc Call Relaying Vulnerability

The rpc service rpc.statd, shipped with all major versions of Sun's solaris, is the status monitoring service for NFS file locking. The vulnerability lies in rpc.statd's ability to relay rpc calls to other rpc services without being validated by the access controls of the other rpc services. This can give the attacker the ability to redirect malicious rpc commands through rpc.statd (which runs as root) to services they may not normally have access to.

Exploit / POC

Solaris rpc.statd rpc Call Relaying Vulnerability

Exploit code is available:

Solution / Fix

Solaris rpc.statd rpc Call Relaying Vulnerability

Solution:
Patches are available to all Sun customers at http://sunsolve.sun.com


Sun Solaris 2.6
  • Sun 106592-02
    sparc


Sun Solaris 2.4_x86

Sun Solaris 2.6_x86
  • Sun 106593-02
    x86


Sun Solaris 2.3
  • Sun 102932-05
    sparc


Sun Solaris 2.5_x86

Sun Solaris 2.4

Sun Solaris 2.5.1 _x86

Sun Solaris 2.5.1
  • Sun 104166-04
    sparc

References

Solaris rpc.statd rpc Call Relaying Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report