Multiple Vendor In.Rarpd Multiple Vulnerabilities
BID:4791
Info
Multiple Vendor In.Rarpd Multiple Vulnerabilities
| Bugtraq ID: | 4791 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0884 CVE-2002-0885 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Credited to "david evlis reign" <[email protected]>. |
| Vulnerable: |
Sun in.rarpd Rarpd in.rarpd Caldera UnixWare 7.1.1 Caldera OpenUnix 8.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor In.Rarpd Multiple Vulnerabilities
Some implementations of rarpd are vulnerable to buffer overflow conditions and format string issues. These problems have been reported in the in.rarpd binaries shipped with versions of Sun Solaris and Caldera Open UNIX and UnixWare.
It has been reported that there seem to be three remotely exploitable buffer overflow conditions, two locally exploitable vulnerabilities, and two format string vulnerabilities.
in.rarpd does not perform proper string formatting when writing entries to syslog. Therefore, it is possible for a remote malicious attacker to craft a request that will result in code execution on the vulnerable system.
Sun Microsystems has reported that these conditions are not exploitable, as data passed to the offending routines is not externally supplied. Furthermore, attackers must be on the local subnet to exploit this vulnerability as ARP packets do not have IP headers and are not routeable. Administrators are still advised to disable or block access to the service if it is not necessary. This record will be updated when more information becomes available.
Some implementations of rarpd are vulnerable to buffer overflow conditions and format string issues. These problems have been reported in the in.rarpd binaries shipped with versions of Sun Solaris and Caldera Open UNIX and UnixWare.
It has been reported that there seem to be three remotely exploitable buffer overflow conditions, two locally exploitable vulnerabilities, and two format string vulnerabilities.
in.rarpd does not perform proper string formatting when writing entries to syslog. Therefore, it is possible for a remote malicious attacker to craft a request that will result in code execution on the vulnerable system.
Sun Microsystems has reported that these conditions are not exploitable, as data passed to the offending routines is not externally supplied. Furthermore, attackers must be on the local subnet to exploit this vulnerability as ARP packets do not have IP headers and are not routeable. Administrators are still advised to disable or block access to the service if it is not necessary. This record will be updated when more information becomes available.
Exploit / POC
Multiple Vendor In.Rarpd Multiple Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor In.Rarpd Multiple Vulnerabilities
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Caldera UnixWare 7.1.1
-
Caldera erg712062.pkg.Z
ftp://ftp.caldera.com/pub/updates/UnixWare/CSSA-2002-SCO.29/erg712062. pkg.Z
Caldera OpenUnix 8.0
-
Caldera erg712062.pkg.Z
ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.29/erg712062. pkg.Z
References
Multiple Vendor In.Rarpd Multiple Vulnerabilities
References:
References: