perl fingerd program allows remote users to execute commands

Risk Level: High risk vulnerability  High

Check or Attack Name: Perl fingerd

Platforms: Perl fingerd: old versions
Description:

A certain, widely distributed, implementation of the finger daemon in Perl could allow remote attackers to execute arbitrary commands on the server with the privileges of the daemon, usually "nobody." This flaw was present through version 0.2 of this program.

Remedy:

This vulnerability existed in the Perl finger daemon through version 0.2, later versions should have corrected this problem.

References:

BUGTRAQ Mailing List, perl fingerd stupidity, http://geek-girl.com/bugtraq/1997_3/0214.html


X-Force Logo
Know Your Risks