Solaris, AIX Login Hole
An anonymous submitter sent in: "A CERT Advisory describes a buffer overflow vulnerability in implementations of login derived from System V, which includes among Solaris 8 and earlier and AIX 4.3/5.1. "An exploit exists and may be circulating." Vendors are testing fixes." There's a Reuters story as well.
Acutally it's been known for a long time that telnet and rlogin are insecure. The effort has been to shift people to secure methods such as OpenSSH for those things. For the most part any sysadmin that has been using telnet and rlogin is probably too lazy to switch. I worked under a sysadmin for a while and it took months of pushing to get him to start implemting SSH across the board.
--- I used to moderate, then I read the -1 articles and decided having to filter through them was not worth it.
This affects systems with telnet or rlogin accessible from the Internet? The implication is that these were somehow not vulnerable without this buffer overrun.
News to me.
Lacking <sarcasm> tags,
Now, what does this mean to you? It means that there's a flaw in login, and any user can gain escalated privileges if they can find a way to call it from a privileged program (if it was suid root, it'd be almost trivial to gain root privs without using telnetd or sshd). The email I pulled the info from was send on december 4th. It was corrected by FreeBSD december 3rd. Obviously in the last week, thousands of solaris boxes have been sitting open to vulnerabilities because they were not notified. And yet, you act as if everyone was told the second it was discovered.
Video for Online Dating Profiles