Total vulnerabilities in the database
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
Software | From | Fixed in |
---|---|---|
caldera / openlinux | 2.4 | 2.4.x |
caldera / openlinux | 2.2 | 2.2.x |
sun / sunos | 5.7 | 5.7.x |
sun / sunos | 5.8 | 5.8.x |
sco / openserver | 5.0.5 | 5.0.5.x |
sun / solaris | 9.0 | 9.0.x |
sco / openserver | 5.0.6a | 5.0.6a.x |
sco / openserver | 5.0.6 | 5.0.6.x |
caldera / openlinux | 2.3 | 2.3.x |