Partner With Us
























CERT Cautions On Sun Cachefs Daemon

Some Sun Solaris units with SPARC and Intel Architectures may be affected by a heap overflow, which may leave a core dump file in the root directory.

May 6, 2002
By Michael Singer: More stories by this author:

Less than a week since it warned against rwall daemon vulnerabilities, officials with CERT Coordination Center said there are again serious holes that may affect some Sun Microsystems servers.

The Internet watchdog late Monday said a heap overflow in Cachefs Daemon (cachefsd) has been identified and there are credible reports of scanning and exploitation of Sun Solaris 2.5.1, 2.6, 7, and 8 (including SPARC and Intel Architectures) running cachefsd.

Cachefsd, which is installed by default with the above servers, caches requests for operations on remote file systems mounted via the use of NFS protocol. A remote attacker can send a crafted RPC request to the cachefsd program to exploit the vulnerability.

If left untreated, Sun said the vulnerability might leave a core dump file in the root directory.

"The presence of the core file does not preclude the success of subsequent attacks." A Sun Alert Notification reports. "Additionally, if the file exists, it may contain unusual entries."

If there is a problem, the networking giant suggests a reboot, or sending a HUP signal to inetd(1M) and kill existing cachefsd processes.

CERT/CC said logs of exploitation attempts might resemble the following:

  • May 16 22:46:08 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Segmentation Fault - core dumped
  • May 16 22:46:21 victim-host last message repeated 7 times
  • May 16 22:46:22 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Bus Error- core dumped
  • May 16 22:46:24 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Segmentation Fault - core dumped
  • May 16 22:46:56 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Bus Error - core dumped
  • May 16 22:46:59 victim-host last message repeated 1 time
  • May 16 22:47:02 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Segmentation Fault - core dumped
  • May 16 22:47:07 victim-host last message repeated 3 times
  • May 16 22:47:09 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Hangup
  • May 16 22:47:11 victim-host inetd[600]: /usr/lib/fs/cachefs/cachefsd: Segmentation Fault - core dumped

So far the vulnerability does not affect similarly classed servers from IBM or SGI

Palo Alto, Calif.-based Sun is asking its customers to check its Alert Notification Web site for the latest patch information.






Business Archives | 7 Day InternetNews Summary | Contact Michael Singer | Back to top

Add internetnews.com
to your browser search box.

IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news
via our XML/RSS:
feed



More InternetNews.com


Hardware Software Mobility Web Content
Search Government Developer Business
Storage E-Commerce Networking Security



internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs