rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=91547759121289&w=2 | mailing list |
http://www.ciac.org/ciac/bulletins/j-045.shtml | third party advisory government resource |
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/186&type=0&nav=sec.sba | vendor advisory |
http://www.securityfocus.com/bid/450 | vdb entry |
http://www.cert.org/advisories/CA-99-05-statd-automountd.html | us government resource third party advisory patch |