CVE-2003-1063: High severity Sun Sunos vulnerability
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For systems running Solaris 2.6 or 7 that have patches 105693-13, 108800-02, 105694-13, or 108801-02 installed (these patches for cachefs are known to overwrite /etc/inetd.conf), inspect /etc/inetd.conf for unexpected or reenabled service entries and remove or disable any services that were unintentionally reenabled to restore the intended security policy.
- Compensating control
Until /etc/inetd.conf is verified and corrected, restrict network access to inetd-managed services at the network edge (firewall/ACL) to only trusted hosts/IP ranges to mitigate potential remote access from reenabled services.
- Operational
Audit Solaris 2.6 and 7 hosts for the presence of patches 105693-13, 108800-02, 105694-13, and 108801-02; for any hosts with those patches present, verify /etc/inetd.conf contents against known-good configuration and remediate discrepancies (restore from backup or edit to intended configuration).
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1063?
CVE-2003-1063 is considered a high severity vulnerability due to its potential to allow remote attackers to bypass security policies.
How do I fix CVE-2003-1063?
To fix CVE-2003-1063, it is essential to apply the appropriate patches that prevent the overwriting of the inetd.conf file.
What systems are affected by CVE-2003-1063?
CVE-2003-1063 affects Solaris 2.6 and Solaris 7.0 systems.
What could potentially happen if CVE-2003-1063 is exploited?
Exploitation of CVE-2003-1063 could lead to the unintended re-enabling of disabled services, increasing the risk of unauthorized access.
Is CVE-2003-1063 still a risk for modern systems?
While CVE-2003-1063 specifically targets older versions of Solaris, systems still using these versions remain at risk if not updated.