|
![]() ![]() |
CERT® Advisory CA-1999-09 Array Services deFA-19ult configurationOriginal release date: July 19, 1999Last revised: -- Source: CERT/CC A complete revision history is at the end of this file. Systems Affected
I. DescriptionA vulnerability has been discovered in the default configuration of the Array Services daemon, arrayd. Array Services are used to manage a cluster of systems. The default configuration file, arrayd.auth, disables authentication and does not provide adequate protection for systems connected to an untrusted network. SGI has published the following document describing the vulnerability and solutions: II. ImpactOn systems installed with the default configuration, remote and local users can execute arbitrary commands as root. III. SolutionUse "SIMPLE" authentication Reconfigure arrayd to use "SIMPLE" authentication. For more information about reconfiguring arrayd, please see the SGI security bulletin. Disable the arrayd daemon If you do not need the capabilities provided by the arrayd daemon, you may wish to disable the daemon. The CERT Coordination Center would like to thank Yuri Volobuev and the SGI Security Team for their assistance in preparing this advisory. This document is available from: http://www.cert.org/advisories/CA-1999-09.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 1999 Carnegie Mellon University. Revision History July 19, 1999: Initial release |








