SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#121099

ypbind contains buffer overflow

Overview

The daemon ypbind on Solaris and SunOS contains a buffer overflow vulnerability.

I. Description

A buffer overflow vulnerability has been discovered in ypbind, a daemon that runs on all client and server machines running Solaris and SunOS and set up to use a Network Information Server (NIS).

II. Impact

This vulnerability may be exploited by a local or a remote attacker to gain root access, and thus complete control of the victim host.

III. Solution

Apply the appropriates patches, available at:
Refer to the following table to see which patch you should apply.

        OS Version          Patch ID        
        __________          _________
        SunOS 5.8           110322-01    
        SunOS 5.8_x86       110323-01    
        SunOS 5.7           108750-02    
        SunOS 5.7_x86       108751-02    
        SunOS 5.6           105403-04  
        SunOS 5.6_x86       105404-04    
        SunOS 5.5.1         105165-04  
        SunOS 5.5.1_x86     105166-04    
        SunOS 5.5           105169-04  
        SunOS 5.5_x86       105170-04    
        SunOS 5.4           101973-41  
        SunOS 5.4_x86       101974-41
None.

Systems Affected

VendorStatusDate NotifiedDate Updated
SunUnknown20-Dec-2001

References

http://sunsolve.sun.com/security
http://sunsolve.sun.com/securitypatch
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/203&type=0&nav=sec.sba
http://xforce.iss.net/static/6828.php

Credit

Thanks to Sun Microsystems for reporting this vulnerability.

This document was written by Shawn Van Ittersum.

Other Information

Date Public:2001-06-26
Date First Published:2002-03-29
Date Last Updated:2002-03-29
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Severity Metric:14.05
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader