HP-UX ypbind Vulnerability
BID:52
Info
HP-UX ypbind Vulnerability
| Bugtraq ID: | 52 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 1992 12:00AM |
| Updated: | Jul 22 1992 12:00AM |
| Credit: | |
| Vulnerable: |
HP HP-UX 8.9 HP HP-UX 8.8 HP HP-UX 8.7 HP HP-UX 8.6 HP HP-UX 8.5 HP HP-UX 8.4 HP HP-UX 8.2 HP HP-UX 8.1 HP HP-UX 8.0 |
| Not Vulnerable: |
HP HP-UX 9.0 |
Discussion
HP-UX ypbind Vulnerability
A vulnerability in HP NIS allows remote NIS servers
unauthorized access to local NIS hosts. An HP NIS client
will accept ypset requests from hosts outside its NIS
domain.
The patch provides a special version of ypbind that only
accepts ypset requests from the local host. This prevents a
superuser on a remote system from issuing a ypset -h
command to the local system to create a rogue ypserver.
This is HP's SR#: 1650-172619.
A vulnerability in HP NIS allows remote NIS servers
unauthorized access to local NIS hosts. An HP NIS client
will accept ypset requests from hosts outside its NIS
domain.
The patch provides a special version of ypbind that only
accepts ypset requests from the local host. This prevents a
superuser on a remote system from issuing a ypset -h
command to the local system to create a rogue ypserver.
This is HP's SR#: 1650-172619.
Exploit / POC
HP-UX ypbind Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
HP-UX ypbind Vulnerability
References:
References:
- HP Electronic Support Center for Europe (Hewlett Packard)
- HP Electronic Support Center for US, Canada, Asia-Pacific, & Latin-America (Hewlett Packard)