Multiple Vendor PCNFSD Remote Command Execution Vulnerability
BID:5378
Info
Multiple Vendor PCNFSD Remote Command Execution Vulnerability
| Bugtraq ID: | 5378 |
| Class: | Input Validation Error |
| CVE: |
CVE-1999-0078 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 1996 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Credit is given to Josh Daymont, Ben G., and Alfred H. of Avalon Security Research. |
| Vulnerable: |
Sun SunOS 4.1.4 Sun SunOS 4.1.3 Sun SunOS 4.1.2 Sun SunOS 4.1.1 Sun SunOS 4.1 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SCO Unixware 2.1 SCO Unixware 2.0.3 SCO Unixware 2.0 SCO Open Server 5.0 IBM AIX 4.2 IBM AIX 4.1 IBM AIX 4.0 IBM AIX 3.2 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.10 HP HP-UX 10.1 0 BSDI BSD/OS 2.1 |
| Not Vulnerable: | |
Discussion
Multiple Vendor PCNFSD Remote Command Execution Vulnerability
pcnfsd, also known as rpc.pcnfsd, is a daemon able to handle authentication and printing over the network. It is available for a wide range of Unix based operating systems.
A vulnerability in some versions of pcnfsd may allow a remote attacker to execute arbitrary commands as the server process. An attacker able to exploit this vulnerability may gain local access to the vulnerable system. pcnfsd normally runs with root privileges.
pcnfsd, also known as rpc.pcnfsd, is a daemon able to handle authentication and printing over the network. It is available for a wide range of Unix based operating systems.
A vulnerability in some versions of pcnfsd may allow a remote attacker to execute arbitrary commands as the server process. An attacker able to exploit this vulnerability may gain local access to the vulnerable system. pcnfsd normally runs with root privileges.
Exploit / POC
Multiple Vendor PCNFSD Remote Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor PCNFSD Remote Command Execution Vulnerability
Solution:
SGI has advised that administrators uninstall the pcnfsd package from IRIX systems. SGI no longer supports the pcnfs package. An updated version has, however, been made available by the SGI Freeware volunteer team:
http://freeware.sgi.com/index-by-alpha.html
Some vendor fixes are available. Details are available in the referenced CERT advisory CA-1996-08.
Solution:
SGI has advised that administrators uninstall the pcnfsd package from IRIX systems. SGI no longer supports the pcnfs package. An updated version has, however, been made available by the SGI Freeware volunteer team:
http://freeware.sgi.com/index-by-alpha.html
Some vendor fixes are available. Details are available in the referenced CERT advisory CA-1996-08.
References
Multiple Vendor PCNFSD Remote Command Execution Vulnerability
References:
References: