Executive brief
A security flaw in the Ultrix and OSF operating systems allows unauthorized remote users to bypass access controls and connect to shared network folders. This could allow an attacker to read, modify, or delete sensitive files stored on the network, even if they were specifically blocked by the system's security settings. This poses a significant risk to data confidentiality and integrity for organizations using these legacy systems.
Technical details
This vulnerability involves a failure in the access control mechanism of the Network File System (NFS) implementation in Digital Equipment Corporation's Ultrix and OSF/1 (Digital UNIX) operating systems. The root cause is an improper validation of the export access list, which allows remote attackers to bypass restrictions and successfully mount exported file systems. An attacker with network access to the NFS server can exploit this without authentication to gain unauthorized read and write access to the underlying data. This bypasses the intended security policy defined in the system's export configuration.
Affected products
- Digital Equipment Corporation Ultrix
- Digital Equipment Corporation OSF/1 (Digital UNIX)
Timeline
- 1997-01-01: disclosed