Compaq
© Copyright 2000 Compaq Computer Corporation. All rights reserved.
SOURCE: Compaq Computer Corporation
Compaq Services
Software Security Response Team USA
re: input validation problem in rpc.statd
This reported problem has not been found to affect the as shipped,
Compaq Tru64/UNIX Operating Systems Software.
- Compaq Computer Corporation
Debian
http://www.debian.org/security/2000/20000719a
FreeBSD
FreeBSD is not vulnerable to this problem.
Hewlett-Packard Company
HP is NOT Vulnerable to the rpc.statd issue in CERT Advisory CA-2000-17.
NetBSD
NetBSD 1.4.x and NetBSD 1.5 do not appear to be affected by this
problem; all calls to syslog() within rpc.statd take a constant string
for the format argument.
OpenBSD
*Linux* systems running the rpc.statd service!
This affects noone else!
RedHat
http://www.redhat.com/support/errata/RHSA-2000-043-03.html
Santa Cruz Operation
The Santa Cruz Operation has investigated this vulnerability and
has determined that NO SCO products are susceptable to it. SCO
does not provide the programs in question, and SCO programs
that perform the same or similar functionality are not susceptable to
this vulnerability.
Silicon Graphics, Inc.
IRIX rpc.statd is not vulnerable to this security issue.
Sun Microsystems, Inc.
Our rpc.statd is not vulnerable to this buffer overflow.
Authors: John Shaffer, Brian King
This document is available from:
http://www.cert.org/advisories/CA-2000-17.html
CERT/CC Contact Information
Email: cert@cert.org
Phone: +1 412-268-7090 (24-hour hotline)
Fax: +1 412-268-6989
Postal address:
-
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
U.S.A.
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4)
Monday through Friday; they are on call for emergencies during other
hours, on U.S. holidays, and on weekends.
Using encryption
We strongly urge you to encrypt sensitive information sent by
email. Our public PGP key is available from
If you prefer to use DES, please call the CERT hotline for more
information.
Getting security information
CERT publications and other security information are available from
our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY
Any material furnished by Carnegie Mellon University and the
Software Engineering Institute is furnished on an "as is"
basis. Carnegie Mellon University makes no warranties of any kind,
either expressed or implied as to any matter including, but not
limited to, warranty of fitness for a particular purpose or
merchantability, exclusivity or results obtained from use of the
material. Carnegie Mellon University does not make any warranty of any
kind with respect to freedom from patent, trademark, or copyright
infringement.