Security Vulnerability in the in.rexecd(1M) Daemon on Kerberos Systems



Category :Security
Release Phase :Resolved
Product :Solaris 10 Operating System  
Bug Id :6371429  
Date of Resolved Release :14-FEB-2006 


Impact

An unprivileged local user may be able to execute arbitrary commands with elevated privileges on Kerberos systems due to a security vulnerability in the in.rexecd(1M) daemon.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

x86 Platform

Note 1: Solaris 8 and Solaris 9 are not affected by this issue.

Note 2: This issue only affects systems with the in.rexecd(1M) service enabled.

To determine if a system has the in.rexecd(1M) service enabled, the svcs(1) command can be run as follows:

    $ svcs svc:/network/rexec:default
    STATE          STIME    FMRI
    online         Jan_27   svc:/network/rexec:default

By default, the in.rexecd(1M) service is disabled on Solaris systems.

Note 3: This issue only affects systems which are configured to reference pam_krb5(5) in their pam.conf(4) file for the "other" column which is typically done as part of configuring a Kerberos client.

To determine if pam_krb5(5) is configured for the "other" service in the "/etc/pam.conf" file the following command can be run:

    $ egrep "^other.*krb5" /etc/pam.conf || echo "Not impacted."
    other   auth sufficient      pam_krb5.so.1

 


Symptoms

There are no reliable symptoms that would indicate the described issue has been exploited to execute arbitrary commands with elevated privilege on a host.


Workaround

Until patches can be applied, sites may wish to disable the in.rexecd(1M) service using the svcadm(1M) command. For example:

    # svcadm disable svc:/network/rexec:default

The service can be re-enabled using svcadm(1M) using the same command syntax as above except with "enable" in place of "disable".


Resolution

This issue is addressed in the following releases:

SPARC Platform

x86 Platform






Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201296
Article Type : Sun Alert
Last reviewed : 2006-11-07
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article