|
Bugtraq
mailing list archives
Re: Sun libnsl lameness
From: nrh () SFX COM (nicholas harteau)
Date: Thu, 2 Jul 1998 00:44:20 -0500
it should be noted that ssh and sshd make use of insecure functions as
mentioned below.
[root () squig ~/work/ssh/ssh-1.2.25] nm sshd | egrep 'getnetname|getsecretkey'
[428] | 372268| 0|FUNC |GLOB |0 |UNDEF |getnetname
[527] | 372280| 0|FUNC |GLOB |0 |UNDEF |getsecretkey
[root () squig ~/work/ssh/ssh-1.2.25] nm ssh | grep getnetname
[416] | 356736| 0|FUNC |GLOB |0 |UNDEF |getnetname
George Clooney wrote:
Functions we have found vulnerable:
Vulnerable key functions
---------------------------------------------------
getsecretkey () : Calls getkeys_nis ()
Vulnerable RPC functions
----------------------------------------------------
getnetname () : Calls host2netname ()
--
nicholas harteau
nrh () sfx com
By Date
By Thread
Current thread:
|