perl fingerd program allows remote users to execute commands |
---|
Risk Level: | High | Check or Attack Name: Perl fingerd |
---|---|---|
Platforms: | Perl fingerd: old versions | |
Description: | A certain, widely distributed, implementation of the finger daemon in Perl could allow remote attackers to execute arbitrary commands on the server with the privileges of the daemon, usually "nobody." This flaw was present through version 0.2 of this program. |
|
Remedy: | This vulnerability existed in the Perl finger daemon through version 0.2, later versions should have corrected this problem. |
|
References: | BUGTRAQ Mailing List, perl fingerd stupidity, http://geek-girl.com/bugtraq/1997_3/0214.html |
Know Your Risks |