Executive brief
A critical vulnerability in the InterNetNews daemon (innd) on IBM AIX systems allows unauthorized individuals to gain remote access to the server. This component is responsible for managing Usenet news feeds, and an exploit could allow an attacker to take full control of the system, potentially leading to data theft or service disruption. Organizations using this legacy software are at high risk of complete system compromise.
Technical details
A remote access vulnerability exists in the InterNetNews daemon (innd) version 1.5.1 as distributed with IBM AIX. The flaw is triggered by the processing of malicious news control messages sent over the network. An unauthenticated attacker can exploit this to gain full administrative control over the affected host. This is a legacy vulnerability involving the improper handling of control messages within the news server architecture. No specific patch details are provided in the historical record, though modern systems are no longer affected by this version.
Affected products
- IBM AIX innd 1.5.1
Timeline
- 1997-01-01: disclosed: Initial publication date