A new vulnerability was identified in Sun Solaris, which may be exploited by local attackers to cause a denial of service. This flaw is due to an unspecified error in the "automountd" daemon when Accessing "/xfn/_x500", which may be exploited by malicious users to create a denial of service.
Note : This issue only occurs if all of the following conditions are true:
- Federated Naming Services (FNS) support for X.500 directory context is installed
- Federated Naming Services (FNS) is enabled in "/etc/auto_master" (This is the default)
- "autofs" is installed and started at boot (This is the default)
- FNS X.500 configuration (/etc/fn/x500.conf) references a valid LDAP server. By default the configuration includes a server named "ldap"
Credits
Vulnerability reported by the vendor
ChangeLog
2005-05-11 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.