High profile Web sites warrant high security
- Publisher
- Elsevier Science
- Year
- 1997
- Tongue
- English
- Weight
- 235 KB
- Volume
- 1997
- Category
- Article
- ISSN
- 1353-4858
No coin nor oath required. For personal study only.
โฆ Synopsis
Vulnerabilities in pluggable authentication module
According to Sun Microsystems Security Bulletin #00139 vulnerabilities exist in certain versions of SunOS. The vulnernable versions are: 5.5.1, 5.5.1-x86, 5.5, 5.5-x86, 5.4, 5.4-x86 and 5.3; those that are not vulnerable are 4.1.4 and 4.1.3_Ul, Because of insufficient bounds checking on arguments in PAM and Unix-scheme, it is possible to overwrite the internal stack space of the passwd program and this vulnerability can be used to gain root access on attacked systems. Under SunOS 5.5.1 and 5.5, yppasswd and nispasswd are hard links to the passwd program and therefore are also vulnerable. Under SunOS 5.4 and 5.3, passwd, yppasswd and nispasswd are separate programs but they dynamically link Unix-scheme and are affected.
๐ SIMILAR VOLUMES