Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
BID:4911
Info
Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
| Bugtraq ID: | 4911 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jun 03 2002 12:00AM |
| Credit: | Originally published in a Sun Alert Notification. |
| Vulnerable: |
Sun Ray Server Software 1.3 |
| Not Vulnerable: |
Sun Ray Server Software 1.2 |
Discussion
Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
Sun Ray Server Software, when configured with NSCM, may allow remote users to inadvertently gain access as an alternate user.
This vulnerability can be exploited remotely by a user whose client is issuing XDMCP to the Sun Ray server. Using the 'dtlogin' facility a remote user is able to login to a Sun Ray Server and find that they are logged in as another user. The remote user does not need an account on the Sun Ray server to take advantage of this vulnerability.
Sun Ray Server Software, when configured with NSCM, may allow remote users to inadvertently gain access as an alternate user.
This vulnerability can be exploited remotely by a user whose client is issuing XDMCP to the Sun Ray server. Using the 'dtlogin' facility a remote user is able to login to a Sun Ray Server and find that they are logged in as another user. The remote user does not need an account on the Sun Ray server to take advantage of this vulnerability.
Exploit / POC
Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
Solution:
The vendor has issued a patch for this vulnerability. Users of SRSS are advised to contact their local Sun Enterprise Service support representative for more information.
Sun Ray Server Software 1.3
Solution:
The vendor has issued a patch for this vulnerability. Users of SRSS are advised to contact their local Sun Enterprise Service support representative for more information.
Sun Ray Server Software 1.3
References
Sun Ray Server Software NSCM Alternate Login Credential Vulnerability
References:
References: