Executive brief
A vulnerability exists in the ypbind service, a component used for managing network information and user accounts on older Linux and SunOS systems. When specific configuration options are enabled, attackers can exploit the service to overwrite critical system files. This could lead to a complete system takeover, data loss, or permanent disruption of operations.
Technical details
The ypbind daemon in Slackware Linux and SunOS contains a path traversal vulnerability when the -ypset or -ypsetme command-line options are enabled. These options are intended to allow the NIS domain binding to be changed, but they fail to properly sanitize input. An attacker can use '..' (dot dot) sequences to escape intended directories and overwrite arbitrary files on the system. This attack can be carried out both locally and over the network without authentication, potentially leading to unauthorized privilege escalation or system compromise.
Affected products
- Slackware Slackware Linux
- Sun Microsystems SunOS
Timeline
- 1997-02-05: disclosed