Berkeley Telnet Kerberos Vulnerability
BID:139
Info
Berkeley Telnet Kerberos Vulnerability
| Bugtraq ID: | 139 |
| Class: | Design Error |
| CVE: |
CVE-1999-1098 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 1998 12:00AM |
| Updated: | May 31 2007 07:31PM |
| Credit: | Mr Spooty ([email protected]) first reported the bug in Bugtraq on Thu, 31 Dec 1998. |
| Vulnerable: |
BSD Telnet 0 |
| Not Vulnerable: | |
Discussion
Berkeley Telnet Kerberos Vulnerability
Berkeley telnet client is prone to a vulnerability that affects the experimental telnet encryption option using Kerberos V4 authentication.
Berkeley telnet client is prone to a vulnerability that affects the experimental telnet encryption option using Kerberos V4 authentication.
Exploit / POC
Berkeley Telnet Kerberos Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Berkeley Telnet Kerberos Vulnerability
Solution:
A patch exists and is available via anonymous FTP from 'net-dist.mit.edu' in the directory '/pub/telnet'.
The patch (which is also included in this message) can be found in the file '/pub/telnet/telnet.patch'. The file '/pub/telnet/telnet.patch.sig' contains a detached PGP signature of this file.
Users of NCSA Telnet should upgrade to the NCSA telnet 2.6.1d4, which is available from 'ftp.ncsa.uiuc.edu' in the directory '/Mac/Telnet/Telnet2.6/prerelease/d4'.
Customers of FTP Software with an encrypting telnet (provided in the PC/TCP or OnNet packages) should call the FTP technical support line at 1-800-282-4387 and ask for the 'tn encrypt patch'.
Solution:
A patch exists and is available via anonymous FTP from 'net-dist.mit.edu' in the directory '/pub/telnet'.
The patch (which is also included in this message) can be found in the file '/pub/telnet/telnet.patch'. The file '/pub/telnet/telnet.patch.sig' contains a detached PGP signature of this file.
Users of NCSA Telnet should upgrade to the NCSA telnet 2.6.1d4, which is available from 'ftp.ncsa.uiuc.edu' in the directory '/Mac/Telnet/Telnet2.6/prerelease/d4'.
Customers of FTP Software with an encrypting telnet (provided in the PC/TCP or OnNet packages) should call the FTP technical support line at 1-800-282-4387 and ask for the 'tn encrypt patch'.