Vulnerability Note VU#538033
ypxfrd daemon fails to properly validate user supplied arguments in "getdbm" procedure
Overview
A vulnerability in the ypxfrd daemon may allow a local attacker to read arbitrary files on the vulnerable system.
Description
Janusz Niewiadomski, of iSEC, discovered this vulnerability and produced the following advisory. Issue: |
Impact
A local attacker my be able to read any file on the vulnerable system. This may lead to privilege escalation. |
Solution
Apply a patch. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| IBM | Affected | 28 Aug 2002 | 10 Oct 2002 |
| Sun Microsystems Inc. | Affected | - | 10 Oct 2002 |
| The SCO Group (SCO UnixWare) | Affected | 28 Aug 2002 | 18 Sep 2002 |
| Apple Computer Inc. | Not Affected | 28 Aug 2002 | 03 Sep 2002 |
| Cray Inc. | Not Affected | 28 Aug 2002 | 04 Sep 2002 |
| Debian | Not Affected | 28 Aug 2002 | 30 Oct 2002 |
| FreeBSD | Not Affected | 28 Aug 2002 | 18 Sep 2002 |
| MandrakeSoft | Not Affected | 28 Aug 2002 | 11 Oct 2002 |
| NEC Corporation | Not Affected | 28 Aug 2002 | 24 Sep 2002 |
| OpenBSD | Not Affected | 28 Aug 2002 | 05 Sep 2002 |
| Red Hat Inc. | Not Affected | 28 Aug 2002 | 29 Aug 2002 |
| SGI | Not Affected | 28 Aug 2002 | 29 Aug 2002 |
| SuSE Inc. | Not Affected | 28 Aug 2002 | 29 Aug 2002 |
| BSDI | Unknown | 28 Aug 2002 | 29 Aug 2002 |
| Conectiva | Unknown | 28 Aug 2002 | 29 Aug 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
Thanks to Janusz Niewiadomski for reporting this vulnerability. We also thank Sun Microsystems for their assistance.
This document was written by Ian A Finlay.
Other Information
- CVE IDs: CAN-2002-1199
- Date Public: 09 Oct 2002
- Date First Published: 10 Oct 2002
- Date Last Updated: 09 Apr 2003
- Severity Metric: 4.50
- Document Revision: 7
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.