Array Services deFA-19ult configuration

Original release date: July 19, 1999
Last revised: --
Source: CERT/CC

A complete revision history is at the end of this file.

Systems Affected

  • IRIX systems running the Array Services daemon
  • UNICOS systems running the Array Services daemon

I. Description

A vulnerability has been discovered in the default configuration of the Array Services daemon, arrayd. Array Services are used to manage a cluster of systems. The default configuration file, arrayd.auth, disables authentication and does not provide adequate protection for systems connected to an untrusted network.

SGI has published the following document describing the vulnerability and solutions:

ftp://sgigate.sgi.com/security/19990701-01-P

II. Impact

On systems installed with the default configuration, remote and local users can execute arbitrary commands as root.

III. Solution

Use "SIMPLE" authentication

Reconfigure arrayd to use "SIMPLE" authentication. For more information about reconfiguring arrayd, please see the SGI security bulletin.

Disable the arrayd daemon

If you do not need the capabilities provided by the arrayd daemon, you may wish to disable the daemon.


The CERT Coordination Center would like to thank Yuri Volobuev and the SGI Security Team for their assistance in preparing this advisory.

Copyright 1999 Carnegie Mellon University.


Revision History
July 19, 1999:  Initial release