IRIX rpc.yppasswdd Unspecified Remote Overflow

High Nessus Plugin ID 11021


Arbitrary code may be run on the remote host.


The remote RPC service #100009 (yppasswdd) is vulnerable to a buffer overflow which allows any user to obtain a root shell on this host.

Note: This issue is different than the one described in CVE-2002-0357 / SGI advisory #20020601-01-P.


Disable this service if you don't use it.

Plugin Details

Severity: High

ID: 11021

File Name: sgi_rpc_passwd.nasl

Version: $Revision: 1.26 $

Type: remote

Family: RPC

Published: 2002/06/08

Modified: 2014/05/26

Dependencies: 10684, 10223

Risk Information

Risk Factor: High


Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: rpc/portmap, Settings/ParanoidReport

Excluded KB Items: rpc/yppasswd/sun_overflow

Vulnerability Publication Date: 2002/06/01

Reference Information

OSVDB: 9727