xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

SGI IRIX rpc.passwd存在缓冲溢出漏洞


发布时间:2002-06-08
更新时间:2002-06-08
严重程度:
威胁程度:远程管理员权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:4939
CVE(CAN) ID:CAN-2002-0357

受影响系统
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.2 m
SGI IRIX 6.5.2 f
SGI IRIX 6.5.2
SGI IRIX 6.5.3 m
SGI IRIX 6.5.3 f
SGI IRIX 6.5.3
SGI IRIX 6.5.4 m
SGI IRIX 6.5.4 f
SGI IRIX 6.5.4
SGI IRIX 6.5.5 m
SGI IRIX 6.5.5 f
SGI IRIX 6.5.5
SGI IRIX 6.5.6 m
SGI IRIX 6.5.6 f
SGI IRIX 6.5.6
SGI IRIX 6.5.7 m
SGI IRIX 6.5.7 f
SGI IRIX 6.5.7
SGI IRIX 6.5.8 m
SGI IRIX 6.5.8 f
SGI IRIX 6.5.8
SGI IRIX 6.5.9 m
SGI IRIX 6.5.9 f
SGI IRIX 6.5.9
SGI IRIX 6.5.10 m
SGI IRIX 6.5.10 f
SGI IRIX 6.5.10
SGI IRIX 6.5.11 m
SGI IRIX 6.5.11 f
SGI IRIX 6.5.11
SGI IRIX 6.5.12 m
SGI IRIX 6.5.12 f
SGI IRIX 6.5.12
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.13
SGI IRIX 6.5.14 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.15
详细描述
SGI报告NIS PASSWORD SERVER的守护程序rpc.passwd存在远程缓冲溢出,利用此漏洞可导致远程攻击者以ROOT权限执行任意命令。尚无具体细节公开。

测试代码
尚无

解决方案
# chmod 444 /usr/etc/rpc.passwd
# killall rpc.passwd

补丁下载:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.12 f:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.12:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.13 m:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.13 f:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.13:

SGI Patch 4588
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4588 Algorithm #1 (sum -r): 15257 9 README.patch.4588 Algorithm #2 (sum): 11291 9 README.patch.4588 MD5 checksum: 6E29360C22F9456717661420D65926D1 Filename: patchSG0004588 Algorithm #1 (sum -r): 13341 3 patchSG0004588 Algorithm #2 (sum): 13931 3 patchSG0004588 MD5 checksum: 57D2491F21C0DC43A5D81C03599813E2 Filename: patchSG0004588.idb Algorithm #1 (sum -r): 37172 2 patchSG0004588.idb Algorithm #2 (sum): 46649 2 patchSG0004588.idb MD5 checksum: C6ECFFB1F4F7C4509554591897AEC3DC Filename: patchSG0004588.nfs_man Algorithm #1 (sum -r): 56602 11 patchSG0004588.nfs_man Algorithm #2 (sum): 9641 11 patchSG0004588.nfs_man MD5 checksum: 023B6AC8AD6677BB982E74993896AB7C Filename: patchSG0004588.nfs_sw Algorithm #1 (sum -r): 11258 18 patchSG0004588.nfs_sw Algorithm #2 (sum): 41577 18 patchSG0004588.nfs_sw MD5 checksum: 80055ED605BEC319E73976A5D6F7DF78

SGI IRIX 6.5.14 m:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

SGI IRIX 6.5.14 f:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

SGI IRIX 6.5.14:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

SGI IRIX 6.5.15 m:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

SGI IRIX 6.5.15 f:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

SGI IRIX 6.5.15:

SGI Patch 4589
http://support.sgi.com/irix/swupdates/
Filename: README.patch.4589 Algorithm #1 (sum -r): 65298 9 README.patch.4589 Algorithm #2 (sum): 13832 9 README.patch.4589 MD5 checksum: B506426BE5B7C68EF1E1780383357AC1 Filename: patchSG0004589 Algorithm #1 (sum -r): 37545 3 patchSG0004589 Algorithm #2 (sum): 15957 3 patchSG0004589 MD5 checksum: AAB01D434DF5F0E7DA46C09BBB16B48C Filename: patchSG0004589.idb Algorithm #1 (sum -r): 04106 2 patchSG0004589.idb Algorithm #2 (sum): 59327 2 patchSG0004589.idb MD5 checksum: F8581C3F06EE1C1446E84F064F8E995F Filename: patchSG0004589.nfs_man Algorithm #1 (sum -r): 22835 16 patchSG0004589.nfs_man Algorithm #2 (sum): 56877 16 patchSG0004589.nfs_man MD5 checksum: 01239B9072D682F82C372A9E10484EE7 Filename: patchSG0004589.nfs_sw Algorithm #1 (sum -r): 08204 58 patchSG0004589.nfs_sw Algorithm #2 (sum): 12173 58 patchSG0004589.nfs_sw MD5 checksum: 6DA112FF943C10C80D0A4A636DD152F2

相关信息