Likewise 'lsassd' Service Remote Denial of Service Vulnerability
BID:47625
Info
Likewise 'lsassd' Service Remote Denial of Service Vulnerability
| Bugtraq ID: | 47625 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1786 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2011 12:00AM |
| Updated: | Apr 29 2011 03:23PM |
| Credit: | VMware |
| Vulnerable: |
VMWare ESXi 4.1 VMWare ESX 4.1 Likewise Software Likewise Open 6.0 Likewise Software Likewise Open 5.3 Likewise Software Likewise Enterprise 6.0 Likewise Software Likewise Enterprise 5.3 |
| Not Vulnerable: |
Likewise Software Likewise Open 6.0 build 8325 Likewise Software Likewise Open 5.3 build 7845 Likewise Software Likewise Enterprise 6.0 build 178 Likewise Software Likewise Enterprise 5.3 build 7845 |
Discussion
Likewise 'lsassd' Service Remote Denial of Service Vulnerability
Likewise is prone to a remote denial-of-service vulnerability because it fails to perform adequate validation checks on user-supplied input.
An attacker can exploit this issue to terminate the Likewise Security Authority ('lsassd') service, triggering a denial-of-service condition.
NOTE (April 29, 2011): This BID was previously titled 'VMware ESXi and ESX Likewise 'lsassd' Service Remote Denial of Service Vulnerability', but has been re-written to reflect the underlying affected technology.
Likewise is prone to a remote denial-of-service vulnerability because it fails to perform adequate validation checks on user-supplied input.
An attacker can exploit this issue to terminate the Likewise Security Authority ('lsassd') service, triggering a denial-of-service condition.
NOTE (April 29, 2011): This BID was previously titled 'VMware ESXi and ESX Likewise 'lsassd' Service Remote Denial of Service Vulnerability', but has been re-written to reflect the underlying affected technology.
Exploit / POC
Likewise 'lsassd' Service Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Likewise 'lsassd' Service Remote Denial of Service Vulnerability
Solution:
Updates are available; please see the references for more information.
VMWare ESX 4.1
VMWare ESXi 4.1
Solution:
Updates are available; please see the references for more information.
VMWare ESX 4.1
-
VMWare ESX410-201104401-SG
https://hostupdate.vmware.com/software/VUM/OFFLINE/release-275-2011042 0-062 017/ESX410-201104001.zip
VMWare ESXi 4.1
-
VMWare ESXi410-201104401-SG
https://hostupdate.vmware.com/software/VUM/OFFLINE/release-276-2011042 0-682 352/ESXi410-201104001.zip
References
Likewise 'lsassd' Service Remote Denial of Service Vulnerability
References:
References:
- Vendor Homepage (Likewise Software)
- VMware Homepage (VMware)
- VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates fo (VMware Security Team
) - [LWSA-2011-001] Lsassd Remote DoS (Likewise)