Executive brief
A vulnerability in the Perl-based fingerd service allows remote attackers to execute unauthorized commands on the host system. This service is typically used to provide information about users on a network. An exploit could lead to a complete system compromise, allowing attackers to access sensitive data or disrupt operations.
Technical details
The Perl implementation of the finger daemon (fingerd) contains a vulnerability that allows for remote command execution. The flaw likely stems from improper sanitization of input passed to the finger service, which is then executed by the Perl interpreter. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the finger port (typically TCP 79). Successful exploitation grants the attacker the ability to run arbitrary shell commands with the privileges of the fingerd process.
Affected products
- Perl fingerd
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD.