[原文]The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.

[CNNVD]Array Services守护程序权限许可漏洞(CNNVD-199907-020)

        Array Services守护程序(arrayd)的默认配置使认证失效,远程用户可以获得根特权。

CVSS分值: 10 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/o:sgi:irix:6.3SGI IRIX 6.3
cpe:/o:sgi:irix:6.2SGI IRIX 6.2
cpe:/o:cray:unicosCray UNICOS
cpe:/o:sgi:irix:6.5.4SGI IRIX 6.5.4
cpe:/o:sgi:irix:6.5.3SGI IRIX 6.5.3
cpe:/o:sgi:irix:6.5.1SGI IRIX 6.5.1
cpe:/o:sgi:irix:6.4SGI IRIX 6.4
cpe:/o:sgi:irix:6.5.2SGI IRIX 6.5.2
cpe:/o:sgi:irix:6.5SGI IRIX 6.5

- OVAL (用于检测的技术细节)


IRIX arrayd Authentication Spoofing Remote Privilege Escalation
Remote / Network Access Input Manipulation
Loss of Integrity
Exploit Public

- 漏洞描述

IRIX and ProPack contain a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an error in arrayd occurs during the processing of authentication requests when configured to use NONE or SIMPLE authentication. Use of the classic exploit may grant a malicious user remote root and lead to a loss of integrity.

- 时间线

2005-06-22 Unknow
1999-08-01 Unknow

- 解决方案

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: switch to NOREMOTE authentication.

