All the latest UK technology news, reviews and analysis

Sun burnt by second bug in a week

by James Middleton

08 May 2002

Be the first to comment

  • Tweet this

Sun Microsystems' Solaris operating system has come a cropper for the second time in a week after the Computer Emergency Response Team (Cert) published another security advisory on Monday.

Coincidentally, the new found vulnerability affects exactly the same version of the operating system as the flaw found in the Solaris rwall daemon last week - 2.5.1, 2.6, 7, and 8 on both Sparc and Intel architectures.

This time, the default installation of the cachefsd daemon is at fault. Cachefsd caches requests for operations on remote file systems using the Network File System protocol.

If an attacker sends a maliciously crafted request to the cachefsd daemon, it becomes possible to remotely execute code with the privileges of the cachefsd process, typically root.

It should also be noted that, according to a Sun Alert Notification, failed attempts to exploit this vulnerability may leave a core dump file in the root directory.

But the presence of the core file does not preclude the success of subsequent attacks.

Cert warned that it has received credible reports of scanning and exploitation of Solaris systems running cachefsd.

It is recommended that users running vulnerable systems download a patch from the Sun website. More information can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Principle Network Design Engineer

Key skills for this role include a comprehensive understanding...

Senior Information Security Consultant

Fantastic opportunity for an Information Security Professional...

VB.NET Developer Cheshire

VB.NET Developer / SQL / VB6 / ASP / XML / Cheshire...

Security Architect

Fantastic opportunity for a high calibre Security Architect...

To send to more than one email address, simply separate each address with a comma.