Title: SGI IRIX rpc.passwd Buffer Overflow Vulnerability
Severity: CRITICAL
Description:
The SGI implementation of NIS is included in the optional package, 'nfs.sw.nis'. This package includes a component for handling NIS password change requests, 'rpc.passwd'. The 'rpc.passwd' service is a network daemon that accepts communications from remote clients.
SGI has reported that 'rpc.passwd' is vulnerable to a remotely exploitable condition that may grant remote attackers root access on affected systems. The technical nature of the vulnerability is not currently known.
It should be noted that 'rpc.passwd' is only present if support for NIS has been installed. Adminstrators may determine if they have installed the 'nfs.sw.nis' package by issuing the following command:
# versions nfs.sw.nis
I = Installed, R = Removed
Name Date Description
I nfs 03/26/2002 Network File System, 6.5.16m
I nfs.sw 03/26/2002 NFS Software
I nfs.sw.nis 03/26/2002 NIS (formerly Yellow Pages) Support
This output indicates that 'nfs.sw.nis' is installed, and the system may be vulnerable. If 'nfs.sw.nis' is not listed, the system is not vulnerable.
Only systems configured as NIS master hosts are vulnerable. Running the 'chkconfig yp' command may determine if YP (NIS) master support is enabled. If the output is 'on', the system may be vulnerable. Furthermore, 'rpc.passwd' will show up in the system process list of the server is running.
Affected Products:
- SGI IRIX 6.5.0
- SGI IRIX 6.5.1
- SGI IRIX 6.5.10
- SGI IRIX 6.5.10 f
- SGI IRIX 6.5.10 m
- SGI IRIX 6.5.11
- SGI IRIX 6.5.11 f
- SGI IRIX 6.5.11 m
- SGI IRIX 6.5.12
- SGI IRIX 6.5.12 f
- SGI IRIX 6.5.12 m
- SGI IRIX 6.5.13
- SGI IRIX 6.5.13 f
- SGI IRIX 6.5.13 m
- SGI IRIX 6.5.14
- SGI IRIX 6.5.14 f
- SGI IRIX 6.5.14 m
- SGI IRIX 6.5.15
- SGI IRIX 6.5.15 f
- SGI IRIX 6.5.15 m
- SGI IRIX 6.5.2
- SGI IRIX 6.5.2 f
- SGI IRIX 6.5.2 m
- SGI IRIX 6.5.3
- SGI IRIX 6.5.3 f
- SGI IRIX 6.5.3 m
- SGI IRIX 6.5.4
- SGI IRIX 6.5.4 f
- SGI IRIX 6.5.4 m
- SGI IRIX 6.5.5
- SGI IRIX 6.5.5 f
- SGI IRIX 6.5.5 m
- SGI IRIX 6.5.6
- SGI IRIX 6.5.6 f
- SGI IRIX 6.5.6 m
- SGI IRIX 6.5.7
- SGI IRIX 6.5.7 f
- SGI IRIX 6.5.7 m
- SGI IRIX 6.5.8
- SGI IRIX 6.5.8 f
- SGI IRIX 6.5.8 m
- SGI IRIX 6.5.9
- SGI IRIX 6.5.9 f
- SGI IRIX 6.5.9 m
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.