Sun rpc.cmsd Remote Overflow

critical Nessus Plugin ID 11418

Language:

Synopsis

Arbitrary code may be run on the remote server.

Description

The remote Sun rpc.cmsd has integer overflow problem in xdr_array. An attacker may use this flaw to execute arbitrary code on this host with the privileges rpc.cmsd is running as (typically, root), by sending a specially crafted request to this service.

Solution

We suggest that you disable this service and apply a new patch.

Plugin Details

Severity: Critical

ID: 11418

File Name: rpc_cmsd_overflow.nasl

Version: 1.24

Type: remote

Family: RPC

Published: 3/19/2003

Updated: 8/22/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: rpc/portmap, Settings/ParanoidReport

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/1/2002

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2002-0391

BID: 5356