SSLTelnetd Remote Syslog Format String Vulnerability
BID:10684
Info
SSLTelnetd Remote Syslog Format String Vulnerability
| Bugtraq ID: | 10684 |
| Class: | Design Error |
| CVE: |
CVE-2004-0640 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | The individual responsible for disclosure of this issue is currently unknown; this issue was disclosed in the referenced iDEFENSE security advisory. b0f is credited with discovering this issue in netkit-telnet-ssl. |
| Vulnerable: |
SSLtelnetd Secure Telnet 0.13 -1 Netkit Linux Netkit 0.17.17 Netkit Linux Netkit 0.17 |
| Not Vulnerable: | |
Discussion
SSLTelnetd Remote Syslog Format String Vulnerability
Reportedly SSLTelnetd, which is available as a FreeBSD port, is affected by a remote format string vulnerability. This issue is due to an improper implementation of the 'syslog()' formatted string function.
As a result of this issue, malicious log entries containing format specifiers will be interpreted literally when logs are written; this may result in attacker-specified memory being corrupted or disclosed, leading to arbitrary code execution.
Linux Netkit netkit-telnet-ssl is affected by this issue as well.
Reportedly SSLTelnetd, which is available as a FreeBSD port, is affected by a remote format string vulnerability. This issue is due to an improper implementation of the 'syslog()' formatted string function.
As a result of this issue, malicious log entries containing format specifiers will be interpreted literally when logs are written; this may result in attacker-specified memory being corrupted or disclosed, leading to arbitrary code execution.
Linux Netkit netkit-telnet-ssl is affected by this issue as well.
Exploit / POC
SSLTelnetd Remote Syslog Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SSLTelnetd Remote Syslog Format String Vulnerability
Solution:
Debian has released advisory DSA 529-1 to address this issue. Please see the attached advisory for details about obtaining and applying fixes.
Netkit Linux Netkit 0.17.17
Solution:
Debian has released advisory DSA 529-1 to address this issue. Please see the attached advisory for details about obtaining and applying fixes.
Netkit Linux Netkit 0.17.17
-
Debian telnet-ssl_0.17.17+0.1-2woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_arm.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_hppa.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_i386.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_ia64.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_m68k.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_mips.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_mipsel.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_powerpc.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_s390.deb -
Debian telnet-ssl_0.17.17+0.1-2woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne t-ssl_0.17.17+0.1-2woody1_sparc.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_arm.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_hppa.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_ia64.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_m68k.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_mips.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_mipsel.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_powerpc.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_s390.deb -
Debian telnetd-ssl_0.17.17+0.1-2woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/n/netkit-telnet-ssl/telne td-ssl_0.17.17+0.1-2woody1_sparc.deb
References
SSLTelnetd Remote Syslog Format String Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- Security Advisory 07.08.04: SSLTelnet Remote Format String Vulnerability (iDEFENSE)