发布时间 :1997-07-14 00:00:00
修订时间 :2018-05-02 21:29:01

[原文]IRIX fam service allows an attacker to obtain a list of all files on the server.

[CNNVD]IRIX fam服务漏洞(CNNVD-199707-023)

        IRIX fam服务存在漏洞。攻击者可以借助该漏洞获得服务器上所有文件的列表。

- CVSS (基础分值)

CVSS分值: 7.1 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: MEDIUM [漏洞利用存在一定的访问条件]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/o:sgi:irix:5.3SGI IRIX 5.3
cpe:/o:sgi:irix:6.1SGI IRIX 6.1
cpe:/o:sgi:irix:6.2SGI IRIX 6.2
cpe:/o:sgi:irix:6.3SGI IRIX 6.3

- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  XF  irix-fam(325)

IRIX fam服务漏洞
高危 其他
1997-07-14 00:00:00 2007-07-13 00:00:00
        IRIX fam服务存在漏洞。攻击者可以借助该漏洞获得服务器上所有文件的列表。

- 公告与补丁

        A suitable temporary solution may be to disable the fam service. It is executed by inetd. Simply comment out the entry in /etc/inetd.conf, make sure all instances of fam are killed, and restart inetd.
        On March 1, 2000, SGI released an advisory on this vulnerability. Fix information was contained within it.

IRIX File Alteration Monitor (fam) Arbitrary Directory Listing
Remote / Network Access Misconfiguration
Loss of Confidentiality Patch / RCS
Vendor Verified

- 漏洞描述

IRIX contains a flaw that may allow a malicious attacker to obtain a complete listing of files and directories on vulnerable systems. The issue is triggered when the File Altercation Monitor (fam) daemon is instructed by a program to monitor the root directory. It is possible that the flaw may allow retrieval of all files under the root directory, resulting in a loss of confidentiality.

- 时间线

1997-07-14 Unknow
Unknow 2000-03-01

- 解决方案

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: disable the fam service by commenting out the entry for it in /etc/inetd.conf, and rebooting.

