|
Ypbind -ypset/-ypsetme Vulnerability
Ypbind is an RPC service that allows NIS clients to locate NIS services on a network. Certain versions of ypbind contain a vulnerability when the service is run with the -ypset and -ypsetme switches than can allow a remote or local user to overwrite certain files on the filesystem. By executing the RPC procedure YPBINDPROC_SETDOMAIN with a path that includes the special path characters '..' it is possible to overwrite or create any file with a '.2' extension. This would allow for example an attacker to overwrite any section 2 man page. |
|
|
Privacy Statement |