Description
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Affected products
- cde / cde1.0.1 – 1.0.1
- cde / cde1.0.2 – 1.0.2
- cde / cde1.1 – 1.1
- cde / cde1.2 – 1.2
- cde / cde2.0 – 2.0
- cde / cde2.1 – 2.1
- cde / cde2.120 – 2.120
- digital / unix4.0d – 4.0d
- digital / unix4.0f – 4.0f
- ibm / aix4.1 – 4.1
- ibm / aix4.1.1 – 4.1.1
- ibm / aix4.1.2 – 4.1.2
- ibm / aix4.1.3 – 4.1.3
- ibm / aix4.1.4 – 4.1.4
- ibm / aix4.1.5 – 4.1.5
- ibm / aix4.2 – 4.2
- ibm / aix4.2.1 – 4.2.1
- ibm / aix4.3 – 4.3
- ibm / aix4.3.1 – 4.3.1
- ibm / aix4.3.2 – 4.3.2
- sun / solaris2.4 – 2.4
- sun / solaris2.5 – 2.5
- sun / solaris2.5.1 – 2.5.1
- sun / solaris2.6 – 2.6
- sun / solaris7.0 – 7.0
- sun / sunos
- sun / sunos4.1.3u1 – 4.1.3u1
- sun / sunos4.1.4 – 4.1.4
- sun / sunos5.3 – 5.3
- sun / sunos5.4 – 5.4
- sun / sunos5.5 – 5.5
- sun / sunos5.5.1 – 5.5.1
- sun / sunos5.7 – 5.7