search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Problem with HP r-cmnds

Vulnerability Note VU#13217

Original Release Date: 2001-12-15 | Last Revised: 2001-12-15

Overview

A problem existed with HP versions of the r-commands (remshd, rexecd, rlogin, rlogind, remsh, rcp, rexec, rdist) in use circa December, 1998.

Description

See HEWLETT-PACKARD COMPANY SECURITY BULLETIN: #00090, (registration required) 07 December 1998 for a description of the problem. No other information is available. Quoting from that bulletin:

Various HP-UX remote network commands (r-cmnds) in the fileset InternetSrvcs.INETSVCS-RUN have been enhanced.  These include remshd(1M), rexecd(1M), rlogind(1M), rlogin(1), remsh(1), rcp(1), rexec(1), and rdist(1). All of these commands have been bundled into one convenient patch to address various operational and security defects noted the recent past.

Impact

The complete impact of this vulnerability is unknown.

Solution

Install a patch as described in the bulletin, or upgrade to a later version.

Vendor Information

13217
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Shawn V Hernan.

Other Information

CVE IDs: None
Severity Metric: 0.42
Date Public: 1999-12-07
Date First Published: 2001-12-15
Date Last Updated: 2001-12-15 02:41 UTC
Document Revision: 6

Sponsored by CISA.