Executive brief
The rpc.ypupdated service, part of the Network Information Service (NIS) used for managing system configuration data across a network, contains a critical security flaw. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the affected server. This could lead to a total compromise of the system, including the theft of sensitive data or a complete shutdown of network services.
Technical details
The rpc.ypupdated daemon, which handles updates to NIS maps, fails to properly validate or sanitize inputs from remote RPC requests. This lack of validation allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands on the host system. The vulnerability is reachable over the network via the RPC portmapper. Successful exploitation grants the attacker the same privileges as the daemon, typically root, leading to full system compromise. This is a legacy vulnerability affecting older Unix-based systems utilizing NIS.
Affected products
- Sun Microsystems ypupdated (NIS)
Timeline
- 1995-12-12: disclosed