|
IRIX rpcbind Symlink Vulnerability
A vulnerability has been discovered in the rpcbind utility available on IRIX operating systems. When starting rpcbind with the '-w' switch, the program attempts to locate a registered services list located in files in the /tmp directory. These files are written to when the rpcbind process receives a SIGINT or SIGTERM signal. Since rpcbind incorrectly follows symbolic links, this may possibly result in arbitrary files being corrupted/overwritten when a SIGINT or SIGTERM signal is received by rpcbind. Critical files which are writeable by the rpcbind process may be corrupted, resulting in a denial of service. It should be noted that rpcbind is included in the 'eoe.sw.svr4net' package, which is not installed by default. |
|
|
Privacy Statement |