rstatd vulnerability


Summary

rstatd provides information about a machine's performance.

Impact

A Bad Guy(tm) could build a table of a machine's usage based on the load average and uptime.

Background

rstatd is normally used to check a machine's load average and availability. Some systems administrators use this information to assess a machine's status without having to log into the machine.

The problem

By knowing when a system is not being used, a cracker could start an attack during off-hours. Also, an attacker might be able to make some assumptions about the machine and its importance.

Fix