HP-UX rlpdaemon Escape Character Vulnerability
BID:102
Info
HP-UX rlpdaemon Escape Character Vulnerability
| Bugtraq ID: | 102 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | May 31 1998 12:00AM |
| Updated: | May 31 1998 12:00AM |
| Credit: | This vulnerability was found by Bwana Brian and published in the RSI.0003.05-15-98.HP-UX.RWITE security advisory. |
| Vulnerable: |
HP HP-UX (VVOS) 10.24 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 HP HP-UX 10.9 HP HP-UX 10.8 HP HP-UX 10.1 0 HP HP-UX 10.0 HP HP-UX 9.10 HP HP-UX 9.9 HP HP-UX 9.8 HP HP-UX 9.7 HP HP-UX 9.6 HP HP-UX 9.5 HP HP-UX 9.4 HP HP-UX 9.3 HP HP-UX 9.1 HP HP-UX 9.0 |
| Not Vulnerable: | |
Discussion
HP-UX rlpdaemon Escape Character Vulnerability
If a user has an hpterm session logged in to an HP-UX that
is running rlpdaemon, it is possible for an attacker to
remotely compromise the active account.
By sending carefully selected packets to the rlpdaemon, an
attacker can force a user's terminal to display a message
that contains escape sequences with embedded commands that
reprogram the soft-keys of the hpterm, allowing for arbitrary
playback and key remapping. The user does not need to have
'mesg y' on for this to happen.
This problem is present in any HP-UX running the current
version of rlpdaemon.
If a user has an hpterm session logged in to an HP-UX that
is running rlpdaemon, it is possible for an attacker to
remotely compromise the active account.
By sending carefully selected packets to the rlpdaemon, an
attacker can force a user's terminal to display a message
that contains escape sequences with embedded commands that
reprogram the soft-keys of the hpterm, allowing for arbitrary
playback and key remapping. The user does not need to have
'mesg y' on for this to happen.
This problem is present in any HP-UX running the current
version of rlpdaemon.
Exploit / POC
HP-UX rlpdaemon Escape Character Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].