J-Security Center

Title: FreeBSD fingerd File Disclosure Vulnerability

Severity: MODERATE

Description:

A vulnerability exists in the version of fingerd that ships with FreeBSD 4.1.1-RELEASE. This vulnerability has to do with a feature that was added to fingerd allowing users to request the contents of certain files (administrator-specified) remotely, via the finger client. Unfortunately, the client can request the contents of any file or listing of any directory on the server's filesystem readable to user 'nobody', bypassing the access restrictions. The information obtained (eg. valid usernames, possibly cgi source code, http passwd files) may be used for more complicated/targeted attacks.

fingerd sets its uid as 'nobody' and executes the finger client locally when opening the requested file. Because of this, reading the contents of "secure" files such as /etc/master.passwd is not possible via this vulnerability.

Affected Products:

  • FreeBSD FreeBSD 4.1.1 -RELEASE

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.