SGI arrayd.auth Default Configuration Vulnerability
BID:530
Info
SGI arrayd.auth Default Configuration Vulnerability
| Bugtraq ID: | 530 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 1999 12:00AM |
| Updated: | Jul 19 1999 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
SGI UNICOS 10.0 6 SGI UNICOS 10.0 5 SGI UNICOS 10.0 4 SGI UNICOS 10.0 3 SGI UNICOS 10.0 2 SGI UNICOS 10.0 1 SGI UNICOS 10.0 SGI UNICOS 9.0 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI Advanced Linux Environment 3.0 |
| Not Vulnerable: | |
Discussion
SGI arrayd.auth Default Configuration Vulnerability
The SGI Array Services provide a mechanism to simplify administering and managing an array of clustered systems. The arrayd(1m) program is part of the array_services(5) and is known as the array services daemon. The default configuration for authorization makes clustered systems vulnerable to remote root compromises. The array services are installed on Irix systems by default from the Irix applications CD. All versions of Unicos post 9.0.0 are vulnerable.
The SGI Array Services provide a mechanism to simplify administering and managing an array of clustered systems. The arrayd(1m) program is part of the array_services(5) and is known as the array services daemon. The default configuration for authorization makes clustered systems vulnerable to remote root compromises. The array services are installed on Irix systems by default from the Irix applications CD. All versions of Unicos post 9.0.0 are vulnerable.
Exploit / POC
SGI arrayd.auth Default Configuration Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
SGI arrayd.auth Default Configuration Vulnerability
Solution:
SGI had initially suggested that setting arrayd authentication to SIMPLE or NONE would be a valid workaround to this issue. SGI has now confirmed that SIMPLE or NONE authentication modes are also vulnerable. NOREMOTE arrayd authentication is not vulnerable.
SGI has released advisory 20050801-01-P to address this issue. Please see the referenced advisory for information on obtaining fixes.
Solution:
SGI had initially suggested that setting arrayd authentication to SIMPLE or NONE would be a valid workaround to this issue. SGI has now confirmed that SIMPLE or NONE authentication modes are also vulnerable. NOREMOTE arrayd authentication is not vulnerable.
SGI has released advisory 20050801-01-P to address this issue. Please see the referenced advisory for information on obtaining fixes.