InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
BID:1001
Info
InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
| Bugtraq ID: | 1001 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 24 2000 12:00AM |
| Updated: | Feb 24 2000 12:00AM |
| Credit: | Posted to Bugtraq on February 24th, 2000 by USSR Labs <[email protected]>. |
| Vulnerable: |
Pragma Systems InterAccess TelnetD Server 4.0 |
| Not Vulnerable: |
Pragma Systems InterAccess TelnetD Server 4.0 Build 8 |
Discussion
InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
The Pragma Systems InterAccess TelnetID Server 4.0 can be crashed by sending invalid, unexpected characters in the client's terminal configuration settings. This causes telnetd.exe to GPF, and will cause the server to stop responding.
The Pragma Systems InterAccess TelnetID Server 4.0 can be crashed by sending invalid, unexpected characters in the client's terminal configuration settings. This causes telnetd.exe to GPF, and will cause the server to stop responding.
Exploit / POC
InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
USSR Labs Exploit:
Executable - dostelnetd.exe
Source - dostelnetd.zip
This exploit triggers a server crash.
USSR Labs Exploit:
Executable - dostelnetd.exe
Source - dostelnetd.zip
This exploit triggers a server crash.
References
InterAccess TelnetD Server 4.0 Terminal Configuration Vulnerability
References:
References:
- Pragma Systems Home Page (Pragma Systems)