Executive brief
A vulnerability in certain versions of the rlogin remote access utility allows unauthorized users to gain full administrative control over a system. By providing a specific command-line parameter, an attacker can bypass standard authentication and log in as the root user. This poses a critical risk to the confidentiality and integrity of the entire server and any data stored on it.
Technical details
The rlogin utility in various Unix-like operating systems contains an argument injection vulnerability (CWE-88). By passing the '-froot' parameter, an attacker can force the service to authenticate the session as the root user without requiring a password. This is a network-based attack that requires no prior authentication. Successful exploitation results in a complete compromise of the target system with highest privileges. The vulnerability was widely addressed in the mid-1990s by patching the rlogin daemon to properly validate or reject such parameters.
Affected products
- Multiple Vendors rlogin
Timeline
- 1994-05-23: disclosed