Executive brief
A configuration flaw in the Network Information Service Plus (NIS+) on Linux systems allowed unauthorized access. Attackers could bypass standard authentication to log in as a special account designated by the '+' character. This could lead to unauthorized access to system resources and potential data compromise on affected legacy systems.
Technical details
This vulnerability stems from a configuration error in the Linux implementation of NIS+ (Network Information Service Plus). Due to improper handling of the '+' wildcard character in system authentication files or NIS+ maps, the system incorrectly validated login attempts for a user named '+'. An attacker with local access could exploit this to gain unauthorized entry into the system. This issue is primarily found in legacy Linux environments where NIS+ was utilized for distributed naming services. The impact includes a loss of confidentiality, integrity, and availability as the attacker gains a foothold on the local system.
Affected products
- Linux NIS+ Legacy Linux distributions using NIS+
Timeline
- 1995-09-07: disclosed: Initial publication date in NVD