Security flaw found in Sun library
InfoWorld | at | by Mike
Security hole in the XDR (External Data Representation) Library provided to a number of vendors by Sun Microsystems could allow an attacker to execute arbitrary code on an affected system or cause a denial of service, according to an advisory released Tuesday by the CERT Coordination Center (CERT/CC). The flaw also affects the widely used Kerberos authentication software that allows users to securely log on to remote systems.
The vulnerability exists in XDR libraries derived from SunRPC (remote procedure call) used in products from Sun, as well as from Apple Computer Inc., IBM Corp. and a number of Linux and Unix distributions, CERT/CC said. These products include those that use the Sun network service library (libnsl), the BSD-derived XDR/RPC routines (libc) and the GNU C library with sunrpc (glibc), CERT/CC said.