vendor:
Solaris
by:
Anonymous
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Solaris
Affected Version From: All major versions of Sun's Solaris
Affected Version To: All major versions of Sun's Solaris
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
1998
RPC.statd Vulnerability
The rpc service rpc.statd, shipped with all major versions of Sun's solaris, is the status monitoring service for NFS file locking. The vulnerability lies in rpc.statd's ability to relay rpc calls to other rpc services without being validated by the access controls of the other rpc services. This can give the attacker the ability to redirect malicious rpc commands through rpc.statd (which runs as root) to services they may not normally have access to.
Mitigation:
Disable the rpc.statd service if it is not needed.