Executive brief
A vulnerability in the automountd service, which automatically manages network file systems, allows attackers to take full control of affected systems. By sending specially crafted commands, an attacker can execute arbitrary code with administrative privileges. This could lead to complete system takeover, data theft, or permanent disruption of operations.
Technical details
The automountd daemon is vulnerable to a command injection flaw because it improperly handles shell metacharacters passed in mount requests. Specifically, the daemon was found to use functions like popen() or improperly sanitized execve() calls when processing map keys. While automountd typically listens on TLI (Transport Layer Interface), it can be reached remotely by bouncing RPC packets through the rpc.statd service using SM_MON and SM_NOTIFY commands. An attacker can exploit this to execute arbitrary shell commands as the root user. Patches were released by Sun (e.g., patch 104654-05) and HP to address the issue.
Affected products
- Sun Microsystems Solaris 2.4, 2.5, 2.5.1, 2.6, 2.7
- Sun Microsystems SunOS 5.4, 5.5, 5.5.1
- HP HP-UX HPSBUX9910-104 affected versions
Timeline
- 1997-11-26: disclosed: Initial exploit for Solaris 2.5.1 posted to Bugtraq
- 1997-11-26: advisory: NVD publication date
- 1999-01-04: other: Detailed analysis of remote exploitation via rpc.statd published