Multiple Vendor rpc.statd Arbitrary File Creation / Deletion Vulnerability
BID:6831
Info
Multiple Vendor rpc.statd Arbitrary File Creation / Deletion Vulnerability
| Bugtraq ID: | 6831 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 1996 12:00AM |
| Updated: | May 10 1996 12:00AM |
| Credit: | The discoverer of this vulnerability is currently unknown. |
| Vulnerable: |
Sun SunOS 4.1.4 Sun SunOS 4.1.3 _U1 Sun SunOS 4.1.3 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 Sony NEWS-OS 6.1.1 Sony NEWS-OS 6.1 Sony NEWS-OS 6.0.3 Sony NEWS-OS 4.2.1 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 SGI IRIX 4.0.5 SGI IRIX 4.0.4 SGI IRIX 4.0.3 SGI IRIX 4.0.2 SGI IRIX 4.0.1 SGI IRIX 4.0 NEC UX/4800 (64) NEC UP-UX/V (Rel4.2MP) NEC Ews-Ux V (Rel4.2MP) NEC Ews-Ux V (Rel4.2) IBM AIX 4.1 IBM AIX 3.2 Data General DG/UX 5.4 4.11 Cray UNICOS 8.3 Cray UNICOS 8.0 Cray UNICOS 7.0 Apple A/UX 3.1.1 Apple A/UX 3.1 |
| Not Vulnerable: |
SGI IRIX 6.5.18 SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SCO Unixware 2.1.3 SCO Unixware 2.1 SCO Unixware 2.0.3 SCO Unixware 2.0 Data General DG/UX 5.4 4.11 MU02 Cray UNICOS 9.2 .4 Cray UNICOS 9.2 Cray UNICOS 9.0.2 .5 Cray UNICOS 9.0 |
Solution / Fix
Multiple Vendor rpc.statd Arbitrary File Creation / Deletion Vulnerability
Solution:
Apple has released fixes for A/UX 3.1 and 3.1.1 from ftp.support.apple.com at the following location:
pub/apple_sw_updates/US/Unix/A_UX/supported/3.x/rpc.statd/rpc.statd.Z
Cray UNICOS 9.0 and higher are not vulnerable.
This issue does not affect Data General DG/UX R4.11 Maintenance Update 2 (R4.11MU02).
Patches are available for HP-UX:
s300/s400 9.X - PHNE_7372 (rpc.statd)
s700/s800 9.X - PHNE_7072 (NFS Megapatch)
s700/s800 10.X - PHNE_7073 (NFS Megapatch)
APARs for IBM AIX are available.
AIX 3.2 - APAR - IX56056 (PTF - U441411)
AIX 4.1 - APAR - IX55931
Patches are available for NCR MP-RAS SVR4 releases:
MP-RAS 2.03.x - PNFS203 (Version after 7/26-96)
MP-RAS 3.00.x - PNFS300 (Version after 8/19-96)
Solution:
Apple has released fixes for A/UX 3.1 and 3.1.1 from ftp.support.apple.com at the following location:
pub/apple_sw_updates/US/Unix/A_UX/supported/3.x/rpc.statd/rpc.statd.Z
Cray UNICOS 9.0 and higher are not vulnerable.
This issue does not affect Data General DG/UX R4.11 Maintenance Update 2 (R4.11MU02).
Patches are available for HP-UX:
s300/s400 9.X - PHNE_7372 (rpc.statd)
s700/s800 9.X - PHNE_7072 (NFS Megapatch)
s700/s800 10.X - PHNE_7073 (NFS Megapatch)
APARs for IBM AIX are available.
AIX 3.2 - APAR - IX56056 (PTF - U441411)
AIX 4.1 - APAR - IX55931
Patches are available for NCR MP-RAS SVR4 releases:
MP-RAS 2.03.x - PNFS203 (Version after 7/26-96)
MP-RAS 3.00.x - PNFS300 (Version after 8/19-96)
References
Multiple Vendor rpc.statd Arbitrary File Creation / Deletion Vulnerability
References:
References: