Sun server appliance open to attack: CERT

By Patrick Gray
13 December 2002 02:20 PM
Tags: raq 4, sun, patrick gray, cert, advisory, vulnerable, appliance, exploit
Users of Sun's RaQ 4 Server appliance have been warned in the latest CERT advisory of a serious vulnerability affecting the units.

"A remotely exploitable vulnerability has been discovered in Sun Cobalt RaQ 4 Server Appliances... may allow remote attackers to execute arbitrary code with superuser privileges," the CERT advisory said.

Ironically the vulnerability only affects Raq 4 units with Sun's Security Hardening Patch (SHP) installed on them.

Perhaps of most concern is the fact that a technique for exploiting this vulnerability has already been developed, and the relevant code has been made available to the public. It's been available from the SecuriTeam website since Saturday.

"An exploit is publicly available and may be circulating," the advisory said.

The CERT Advisory contains a link to Sun's instructions on how to remove the SHP, however the link retrieves an "error opening document" message. The link to the "SHP Removal patch" is working.

CERT had made their "vulnerability notes" about the RaQ 4 unit public as far back as the 5th of December, however the full-blown advisory was not published until yesterday.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured