Executive brief
A vulnerability in the HP ypbind service allows users with administrative privileges to improperly modify Network Information Service (NIS) data. NIS is a system used to manage and distribute configuration data, such as user accounts and hostnames, across a network of computers. If exploited, this could allow an attacker to manipulate centralized directory information, potentially leading to unauthorized access or disruption of network services.
Technical details
The HP ypbind daemon, which facilitates communication between NIS clients and servers, contains a vulnerability that allows an attacker with root privileges to modify NIS data. While the specific mechanism of the flaw is not detailed in the legacy advisory, it involves the improper handling of NIS domain binding or data updates. An attacker with local root access or the ability to impersonate a trusted administrative entity can manipulate the NIS maps. This can result in the corruption of network-wide configuration data, including password files and host tables. The vulnerability is primarily relevant to legacy HP-UX environments utilizing NIS for directory services.
Affected products
- HP HP-UX
- HP ypbind
Timeline
- 1993-01-13: disclosed: Initial publication date in NVD