Executive brief
A critical vulnerability exists in the InterNetNews (INN) daemon, a service used to manage Usenet news feeds. By sending specially crafted control messages, an attacker can execute unauthorized commands on the server. This could lead to a complete system takeover, data theft, or disruption of news services.
Technical details
The InterNetNews (INN) daemon (innd) version 1.5 is vulnerable to OS command injection (CWE-78). The vulnerability exists because the daemon fails to properly neutralize shell metacharacters in administrative control messages such as 'newgroup' and 'rmgroup'. A remote, unauthenticated attacker can exploit this by sending malicious control messages over the network, leading to arbitrary command execution with the privileges of the innd process. This allows for full system compromise without requiring user interaction.
Affected products
- ISC InterNetNews (INN) daemon (innd) 1.5
Timeline
- 1996-12-04: disclosed