vendor:
rpc.pcnfsd
by:
Rodrigo Rubira Branco
7,5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: rpc.pcnfsd
Affected Version From: AIX 6.1.0 and lower
Affected Version To: AIX 6.1.0 and lower
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX
Unknown
rpc.pcnfsd syslog format string vulnerability
This exploit is used to exploit a format string vulnerability in the rpc.pcnfsd service. The exploit sends a malicious string to the service which is then used to call the syslog function, resulting in the execution of arbitrary code. The exploit has been tested against AIX 6.1.0 and lower.
Mitigation:
The best way to mitigate this vulnerability is to ensure that the rpc.pcnfsd service is not running on the system.