Korean
<< Back
VID 17025
Severity 40
Port 111
Protocol TCP,UDP
Class RPC
Detailed Description The cmsd RPC service is running. This service has a long history of security holes, so you should really know what you are doing if you decide to let it run.
Recommendation Disable the 'cmsd' rpc service if it's not needed, or use it after asking to the vendor whether not to be vulnerable.

Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
1. you become a root, and then stop the service like the following:

# rpcinfo -d [program num] [version num]

2. comment its entry by putting a # at the beginning of the line with 'cmsd' in /etc/rpc
3. # pkill -HUP (x)inetd
Related URL CVE-1999-0320 (CVE)
Related URL 428 (SecurityFocus)
Related URL 818 (ISS)