Executive brief
A security misconfiguration exists in the NIS+ directory service, which is used to manage administrative information like user accounts across a network. Critical system tables, such as the password file, have incorrect access permissions. This could allow a local user to gain unauthorized access to sensitive system data or modify administrative records, potentially leading to a full system takeover.
Technical details
This vulnerability involves an insecure default configuration or manual misconfiguration of permissions within the Network Information Service Plus (NIS+) directory service. Specifically, system-critical tables like 'passwd' are set with inappropriate access control lists (ACLs). A local attacker with access to the system can exploit these weak permissions to read sensitive information or modify table entries. This can result in a complete compromise of confidentiality, integrity, and availability (CIA) for the affected administrative domain. The issue is typically resolved by auditing and restricting NIS+ table permissions to authorized administrators only.
Affected products
- Sun Microsystems NIS+
Timeline
- 1996-05-28: disclosed: NVD Published Date