HZFQ.COM
welcome to my space
X
Welcome to:hzfq.com
Search:  
 HOME   SunRPC-Derived XDR Library Contains Bug

SunRPC-Derived XDR Library Contains Bug

Published by: webmaster 2008-12-01
A potentially dangerous vulnerability has been detected in SunRPC-derived XDR libraries and the CERT Coordination Center (CERT/CC) has warned that exploitation could lead to denial of service, execution of arbitrary code, or the disclosure of sensitive information.

In an advisory, CERT warned that the integer overflow xdr_array() function in Sun Microsystems' XDR library can lead to remotely exploitable buffer overflows in multiple applications.

Although the XDR library was originally distributed by Sun Microsystems, multiple vendors have included the vulnerable code in their own implementations, the center said, urging individual vendor patches be implemented to guard against remote attacks.

The bug, which was detected by Internet Security Systems (ISS), affected applications like Sun Microsystems network services library (libnsl), BSD-derived libraries with XDR/RPC routines (libc) and the GNU C library with sunrpc (glibc).

"Specific impacts reported include the ability to execute arbitrary code with root privileges (by exploiting dmispd, rpc.cmsd, or kadmind, for example). In addition, intruders who exploit the XDR overflow in MIT KRB5 kadmind may be able to gain control of a Key Distribution Center (KDC) and improperly authenticate to other services within a trusted Kerberos realm," CERT warned.

Security flaw hits Windows, Mac, Linux: News - Security - ZDNet Australia::
libraries are derived from Sun Microsystems SunRPC remote procedure call A function in Suns XDR library contains an integer overflow that can lead to
http://www.zdnet.com.au/news/security/soa/Security-flaw-hi30061744,120267239,00.htm
HOME
lists.grok.org.uk/pipermail/full-disclosure/2002-September.txt::
are documented as Cisco bug IDs CSCdt56514, CSCdu15622, CSCdu35577, CSCdu82823, code derived from the | | | BSD source and are | | | vulnerable to a buffer
http://lists.grok.org.uk/pipermail/full-disclosure/2002-September.txt
HOME
The XDR libraries provide platform-independent methods for sending data from one system process to another over a network connection. The group said the xdr_array() function in the XDR library contained an integer overflow that can lead to improperly sized dynamic memory allocation.

"Subsequent problems like buffer overflows may result, depending on how and where the vulnerable xdr_array() function is used," it added.

Research from the ISS showed the bug allowed the execution of arbitrary code with root privileges (exploiting dmispd, rpc.cmsd, or kadmind, for example). In addition, the security researchers found intruders who exploited the XDR overflow in MIT KRB5 kadmind could gain control of a Key Distribution Center (KDC) and improperly authenticate to other services within a trusted Kerberos realm.

Because the XDR libraries are used by multiple applications on most systems, CERT urged an immediate software upgrade. Users should also apply multiple patches and then recompile statically linked applications.


Uniform Code Council, RosettaNet Merge
iPlanet, Netscape Enterprise Servers at Risk

You are looking at:hzfq.com's SunRPC-Derived XDR Library Contains Bug, click hzfq.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about SunRPC-Derived XDR Library Contains Bug , Please add it free.
  • sell yourself on myspace
  • spam protection know thy enemy viruses and malware trojans and adware
  • problems with internet banking
  • popular email scams on the internet today
  • transferring funds through internet banking
  • spam what is your protection under the law
  • promoting your business on myspace
  • the costs of spam
  • using message boards for internet marketing
  • uploading files to myspace
  • using affiliate marketing to promote your business
  • the fine line between internet marketing and spam
  • security measures taken by internet banking companies
  • using your content for internet marketing

  • using a website to market your business
  • the next generation of spam image and pdf spam
  • using quicken for internet banking
  • the pitfalls of advertising on myspace
  • tips for s on myspace
  • starting an affiliate marketing campaign
  • the importance of seo in internet marketing
  • the what who where and why of spam
  • tracking the results of internet marketing
  • using online courses for internet marketing
  • security and privacy on myspace
  • sell your products on myspace
  • the myspace phenomenon
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzfq.com        Site made:CFZ