Preface: RPC SNMPXDMID overflowLogo -Internet Security Systems

RPC SNMPXDMID overflow

advICE :Intrusions : 2001734
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?

Summary

Probably attack against the SNMPXDMID buffer overflow vulnerability.

Details

Sun Solaris versions 2.6, 7, and 8 are vulnerable to a buffer overflow in the snmpXdmid daemon. The 'snmpXdmid' service is a mapping tool for SNMP and DMI (Desktop Management Interface) requests and is installed with root privileges. By causing the snmpXdmid daemon to translate a malformed DMI request into an SNMP trap, a remote attacker can overflow a buffer to gain root access to the system.

 more information
BugtraqID: 2417  
 
CERT: CA-2001-05   CERT Advisory Exploitation of snmpXdmid
 
CIAC: I-065  
 
CVE-2001-0236   Buffer overflow in Solaris snmpXdmid
 
 
Version appeared: 3.0 

Privacy Policy |  Copyright Info