Multiple Vendor Automountd Vulnerability
BID:729
Info
Multiple Vendor Automountd Vulnerability
| Bugtraq ID: | 729 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 1999 12:00AM |
| Updated: | Jun 09 1999 12:00AM |
| Credit: | Exposed in CERT advisory CA-99-05 on June 9, 1999. |
| Vulnerable: |
Sun Solaris 2.5.1 SGI IRIX 6.2 HP HP-UX 11.0 |
| Not Vulnerable: |
Sun Solaris 7.0 Sun Solaris 2.6 SGI IRIX 6.5.4 |
Discussion
Multiple Vendor Automountd Vulnerability
Automountd is remotely exploitable via an overflowable buffer. This attack can also be relayed through statd, as was described in the CERT advisory CA-99-05. Consequently, an attacker can remotely execute arbitrary code as root, leading to a complete system compromise.
Automountd is remotely exploitable via an overflowable buffer. This attack can also be relayed through statd, as was described in the CERT advisory CA-99-05. Consequently, an attacker can remotely execute arbitrary code as root, leading to a complete system compromise.
Solution / Fix
Multiple Vendor Automountd Vulnerability
Solution:
HP-UX:
A temporary solution is to set AutoFS = 0 in /etc/rc.config.d/nfsconf.
Patches are available at HP Support at http://www.hp.com/go/support
Patches are available for the following platforms:
SGI:
visit
ftp://sgigate.sgi.com/patches/
Sun:
Patches are available to all Sun customers at http://sunsolve.sun.com/
HP HP-UX 11.0
Sun Solaris 2.5.1
Solution:
HP-UX:
A temporary solution is to set AutoFS = 0 in /etc/rc.config.d/nfsconf.
Patches are available at HP Support at http://www.hp.com/go/support
Patches are available for the following platforms:
SGI:
visit
ftp://sgigate.sgi.com/patches/
Sun:
Patches are available to all Sun customers at http://sunsolve.sun.com/
HP HP-UX 11.0
-
HP PHNE_28102
http://itrc.hp.com/
Sun Solaris 2.5.1
References
Multiple Vendor Automountd Vulnerability
References:
References:
- HP Support (Hewlett Packard)
- Sunsolve Online(tm) (Sun Microsystems)