[UNIX] Remote Root Vulnerability in dtlogin
From: SecuriTeam (support_at_securiteam.com)
Date: 03/25/04
- Previous message: SecuriTeam: "[NT] Nexgen FTP Server Directory Traversal Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 25 Mar 2004 17:05:48 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Remote Root Vulnerability in dtlogin
------------------------------------------------------------------------
SUMMARY
A weakness in the XDMCP parser of dtlogin (CDE) allows a remote attacker
to cause the program to execute arbitrary.
DETAILS
Vulnerable Systems:
* Solaris version 8, possibly other versions and flavours of UNIX
Immune Systems:
* Linux
dtlogin is the process in Solaris (and HP-UX, AIX and other UNIX systems
that support CDE) that implements the XDMCP protocol. The protocol is used
whenever an X-query host:port is issued. The service listens on UDP port
177 and in order to exploit the vulnerability no authentication is
required and dtlogin is turned on by default. The dtlogin process runs
with root privileges.
The dtlogin program is also responsible for displaying the login screen so
killing it blindly is not recommended.
ADDITIONAL INFORMATION
The information has been provided by <mailto:dave@immunitysec.com> Dave
Aitel.
The original article can be found at:
<http://www.immunitysec.com/downloads/dtlogin.sxw.pdf>
http://www.immunitysec.com/downloads/dtlogin.sxw.pdf
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NT] Nexgen FTP Server Directory Traversal Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|