SGI IRIX rpc.xfsmd Weak Authentication Vulnerability

Solution:
SGI has stated that the product is being retired. No patches will be produced. Instructions have been provided for disabling the service:

From the SGI advisory:

To disable the product from running, perform the following steps:

# killall /usr/etc/xfsmd
# vi /etc/inetd.conf

Look for a line in inetd.conf that looks like this:

sgi_xfsmd/1 stream rpc/tcp wait root ?/usr/etc/xfsmd xfsmd

...and comment it out by putting a "#" at the beginning of the line:

#sgi_xfsmd/1 stream rpc/tcp wait root ?/usr/etc/xfsmd xfsmd

...or simply remove the line from the file.

# killall -HUP inetd

To remove the product from the system, perform the following command:

# versions remove eoe.sw.xfsmserv



 

Privacy Statement
Copyright 2010, SecurityFocus