Multiple Vendor Linux NIS Vulnerabilities
BID:753
Info
Multiple Vendor Linux NIS Vulnerabilities
| Bugtraq ID: | 753 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 01 1999 12:00AM |
| Updated: | Nov 01 1999 12:00AM |
| Credit: | Debian, RedHat and SuSE all released advisories about this issue within 24 hours of each other, however no credit was given in any of them. |
| Vulnerable: |
SuSE Linux 6.0 Redhat Linux 6.0 Redhat Linux 5.0 Redhat Linux 4.0 Linux kernel 2.3 Linux kernel 2.2 Linux kernel 2.1 Linux kernel 2.0 Debian Linux 2.2 Debian Linux 2.1 Debian Linux 2.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Linux NIS Vulnerabilities
ypserv releases previous to 1.3.9 contain two different vulnerabilties: Any NIS domain administrator can inject password tables, and users can modify the GECOS field and login shell values for other users. Also, rpc.yppasswd prior 1.3.6.92 has a standard buffer overflow problem in the md5 hash generation code.
ypserv releases previous to 1.3.9 contain two different vulnerabilties: Any NIS domain administrator can inject password tables, and users can modify the GECOS field and login shell values for other users. Also, rpc.yppasswd prior 1.3.6.92 has a standard buffer overflow problem in the md5 hash generation code.
Exploit / POC
Multiple Vendor Linux NIS Vulnerabilities
See discussion.
See discussion.