Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

BID:11313

Info

Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

Bugtraq ID: 11313
Class: Design Error
CVE: CVE-2004-0911
Remote: Yes
Local: No
Published: Oct 03 2004 12:00AM
Updated: Jul 12 2009 07:06AM
Credit: This vulnerability was reported to the vendor by Michal Zalewski.
Vulnerable: Debian telnetd-ssl 0.17.17 +0.1-2woody1
Debian telnetd-ssl 0.17.17 +0.1-2
Debian telnetd-ssl 0.17.17 +0.1-1
Debian telnetd 0.17 -25
Debian telnetd 0.17 -18
Not Vulnerable: Debian telnetd-ssl 0.17.17 +0.1-2woody2
Debian telnetd 0.17 -26
Debian telnetd 0.17 -18woody1

Discussion

Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

Telnetd as provided by Debian/GNU Linux is reported susceptible to an invalid memory handling vulnerability. This issue is due to a failure of the application to ensure that memory buffers are properly allocated and deallocated.

It is conjectured that attackers may potentially leverage this vulnerability to execute code in the context of the telnetd process. Debian GNU/Linux runs the process as the unprivileged 'telnetd' user by default.

Versions of telnetd prior to 0.17-18woody1 for the stable branch, and 0.17-26 for the unstable branch are reported to be affected by this vulnerability.

Exploit / POC

Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

Solution:
Debian GNU/Linux has released advisory DSA 556-1, along with fixes to address this issue.

Debian Linux has released advisory DSA 569-1 dealing with this issue for their telnet-ssl distribution. Please see the referenced advisory for more information.

Debian has released DSA 556-2, which is a revision to their first advisory. This revision includes new fixes that reportedly resolve the issue where the original fixes did not. Please see the referenced advisory for more information.


Debian telnetd 0.17 -18

Debian telnetd-ssl 0.17.17 +0.1-2woody1

References

Debian GNU/Linux Telnetd Invalid Memory Handling Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report