Sun Solaris in.rwhod(1M) daemon allows execution of code
| solaris-inrwhod-command-execution (18385) |
Description:
Sun Solaris could allow a remote attacker to execute arbitrary code, caused by a vulnerability in the in.rwhod(1M) daemon. If the in.rwhod(1M) daemon is enabled, which is not the default setting, a remote attacker with privileges could execute arbitrary code on the system with root privileges.
Consequences:
Gain Access
Remedy:
For Sun Solaris:
Apply the appropriate patch for your system, as listed below. Refer to Sun Alert ID: 57659 for more information. See References.
SPARC Platform:
Solaris 7 with patch: 118239-01 or later
Solaris 8 with patch: 116984-01 or later
Solaris 9 with patch: 117455-01 or later
x86 Platform:
Solaris 7 with patch: 118240-01 or later
Solaris 8 with patch: 116985-01 or later
Solaris 9 with patch: 117456-01 or later
References:
- CIAC Information Bulletin P-050: "in.rwhod" Daemon Vulnerability.
- Sun Alert ID: 57659: Security Vulnerability in the in.rwhod(1M) Daemon.
- BID-11840: Sun Solaris IN.RWHOD(1M) Daemon Remote Code Execution Vulnerability
- CVE-2004-1351: Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.
Platforms Affected:
- Sun Solaris 7.0
- Sun Solaris 8
- Sun Solaris 9
Reported:
Dec 06, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
