ypxfrd Local File Disclosure Vulnerability
BID:5937
Info
ypxfrd Local File Disclosure Vulnerability
| Bugtraq ID: | 5937 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1199 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery credited to Janusz Niewiadomski <[email protected]> |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 SCO Open Server 5.0.6 a SCO Open Server 5.0.6 SCO Open Server 5.0.5 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.26 HP HP-UX 10.20 SIS HP HP-UX 10.20 Series 800 HP HP-UX 10.20 Series 700 HP HP-UX 10.20 Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 PK6 (BL20) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.0 a PK3 (BL17) Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 f PK7 (BL18) Caldera OpenLinux 2.4 Caldera OpenLinux 2.3 Caldera OpenLinux 2.2 |
| Not Vulnerable: | |
Discussion
ypxfrd Local File Disclosure Vulnerability
A vulnerability has been discovered in ypxfrd.
Reportedly, ypxfrd fails to sufficently validate user supplied arguments. This issue could be exploited to disclose arbitrary ypxfrd readable files.
If running as a privileged user, exploiting this issue could allow an attacker to access sensitive files, such as a system's shadow file.
The exact operating system releases that are vulnerable to this issue have not yet been confirmed, but it is assumed that the latest versions are affected.
Under some circumstances, depending on the configuration of the vulnerable system, it may be possible for dbm files to be viewed by a remote attacker.
*** It should be noted that this may be the same issue as bid 5912, but due to conflicting reports, we are treating it as a seperate issue.
A vulnerability has been discovered in ypxfrd.
Reportedly, ypxfrd fails to sufficently validate user supplied arguments. This issue could be exploited to disclose arbitrary ypxfrd readable files.
If running as a privileged user, exploiting this issue could allow an attacker to access sensitive files, such as a system's shadow file.
The exact operating system releases that are vulnerable to this issue have not yet been confirmed, but it is assumed that the latest versions are affected.
Under some circumstances, depending on the configuration of the vulnerable system, it may be possible for dbm files to be viewed by a remote attacker.
*** It should be noted that this may be the same issue as bid 5912, but due to conflicting reports, we are treating it as a seperate issue.
Exploit / POC
ypxfrd Local File Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ypxfrd Local File Disclosure Vulnerability
Solution:
Fixes available:
Sun Solaris 9
Sun Solaris 8_x86
Sun Solaris 2.6
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 f PK7 (BL18)
Compaq Tru64 5.0 a PK3 (BL17)
SCO Open Server 5.0.5
SCO Open Server 5.0.6
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 PK5 (BL19)
Solution:
Fixes available:
Sun Solaris 9
-
Sun 113579-01
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 109329-03
http://sunsolve.sun.com
Sun Solaris 2.6
-
Sun 108890-02
http://sunsolve.sun.com
Sun Solaris 8_sparc
-
Sun 109328-03
http://sunsolve.sun.com
Sun Solaris 2.6_x86
-
Sun 108891-02
http://sunsolve.sun.com
Compaq Tru64 4.0 g PK3 (BL17)
-
HP T64V40GB17-C0021401-15597-ES-20020930
http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64v40gb17-c00 21401-15597-es-20020930.tar
Compaq Tru64 4.0 f PK7 (BL18)
-
HP DUV40FB18-C0083701-15595-ES-20020930
http://ftp.support.compaq.com/patches/public/unix/v4.0f/duv40fb18-c008 3701-15595-es-20020930.tar
Compaq Tru64 5.0 a PK3 (BL17)
-
HP T64V50AB17-C0024501-15600-ES-20021001
http://ftp.support.compaq.com/patches/public/unix/v5.0a/t64v50ab17-c00 24501-15600-es-20021001.tar
SCO Open Server 5.0.5
-
SCO CSSA-2002-SCO.40
ftp://ftp.caldera.com/pub/updates/OpenServer/CSSA-2002-SCO.40
SCO Open Server 5.0.6
-
SCO CSSA-2002-SCO.40
ftp://ftp.caldera.com/pub/updates/OpenServer/CSSA-2002-SCO.40
Compaq Tru64 5.1 a PK3 (BL3)
-
HP T64V51AB3-C0065801-15605-ES-20021001
http://ftp.support.compaq.com/patches/public/unix/v5.1a/t64v51ab3-c006 5801-15605-es-20021001.tar
Compaq Tru64 5.1 PK5 (BL19)
-
HP T64V51B19-C0149501-15602-ES-20021001
http://ftp.support.compaq.com/patches/public/unix/v5.1/t64v51b19-c0149 501-15602-es-20021001.tar
References
ypxfrd Local File Disclosure Vulnerability
References:
References:
- HPSBUX0401-306 (HP)
- Sun Alert ID: 47903 (Sun)