๐”– Bobbio Scriptorium
โœฆ   LIBER   โœฆ

High profile Web sites warrant high security


Publisher
Elsevier Science
Year
1997
Tongue
English
Weight
235 KB
Volume
1997
Category
Article
ISSN
1353-4858

No coin nor oath required. For personal study only.

โœฆ Synopsis


Vulnerabilities in pluggable authentication module

According to Sun Microsystems Security Bulletin #00139 vulnerabilities exist in certain versions of SunOS. The vulnernable versions are: 5.5.1, 5.5.1-x86, 5.5, 5.5-x86, 5.4, 5.4-x86 and 5.3; those that are not vulnerable are 4.1.4 and 4.1.3_Ul, Because of insufficient bounds checking on arguments in PAM and Unix-scheme, it is possible to overwrite the internal stack space of the passwd program and this vulnerability can be used to gain root access on attacked systems. Under SunOS 5.5.1 and 5.5, yppasswd and nispasswd are hard links to the passwd program and therefore are also vulnerable. Under SunOS 5.4 and 5.3, passwd, yppasswd and nispasswd are separate programs but they dynamically link Unix-scheme and are affected.


๐Ÿ“œ SIMILAR VOLUMES