Multiple Vendor talkd(8) Vulnerability

BID:210

Info

Multiple Vendor talkd(8) Vulnerability

Bugtraq ID: 210
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: Yes
Published: Jan 18 1997 12:00AM
Updated: Jan 18 1997 12:00AM
Credit: This bug was initially posted to Comp.Security.Unix in July of 1997 by an anonymous poster. It was later followed by multiple vendor and FIRST agency advisories.
Vulnerable: SGI IRIX 6.4
SGI IRIX 6.3
SGI IRIX 6.2
SGI IRIX 6.1
SGI IRIX 6.0.1 XFS
SGI IRIX 6.0.1
SGI IRIX 6.0
SGI IRIX 5.3 XFS
SGI IRIX 5.3
SGI IRIX 5.2
SGI IRIX 5.1.1
SGI IRIX 5.1
SGI IRIX 5.0.1
SGI IRIX 5.0
SGI IRIX 4.0.5 IPR
SGI IRIX 4.0.5 H
SGI IRIX 4.0.5 G
SGI IRIX 4.0.5 F
SGI IRIX 4.0.5 E
SGI IRIX 4.0.5 D
SGI IRIX 4.0.5 A
SGI IRIX 4.0.5 (IOP)
SGI IRIX 4.0.5
SGI IRIX 4.0.4 T
SGI IRIX 4.0.4 B
SGI IRIX 4.0.4
SGI IRIX 4.0.3
SGI IRIX 4.0.2
SGI IRIX 4.0.1
SGI IRIX 4.0
Redhat Linux 3.0.3
Redhat Linux 2.1
Redhat Linux 2.0
NEC UX/4800 (64)
NEC UP-UX/V (Rel4.2MP)
NEC Ews-Ux V (Rel4.2MP)
NEC Ews-Ux V (Rel4.2)
IBM AIX 4.2
IBM AIX 4.1
IBM AIX 3.2
HP HP-UX (VVOS) 10.24
HP HP-UX 10.34
HP HP-UX 10.30
HP HP-UX 10.20
HP HP-UX 10.16
HP HP-UX 10.10
HP HP-UX 10.9
HP HP-UX 10.8
HP HP-UX 10.1 0
HP HP-UX 10.0
FreeBSD FreeBSD 2.1.6
FreeBSD FreeBSD 2.1.5
FreeBSD FreeBSD 2.1
FreeBSD FreeBSD 2.0.5
FreeBSD FreeBSD 2.0
FreeBSD FreeBSD 1.1.5 .1
Debian Linux 1.1
Debian Linux 0.93
BSDI BSD/OS 2.1
BSDI BSD/OS 2.0.1
BSDI BSD/OS 2.0
BSDI BSD/OS 1.1
Not Vulnerable: SGI IRIX 6.5
Redhat Linux 5.2 i386
Redhat Linux 5.1
- Standard & Poors ComStock 4.2.4
Redhat Linux 5.0
Redhat Linux 4.2
Redhat Linux 4.1
Redhat Linux 4.0
IBM AIX 4.3
IBM AIX 4.2.1
FreeBSD FreeBSD 3.1
FreeBSD FreeBSD 3.0
FreeBSD FreeBSD 2.2.8
FreeBSD FreeBSD 2.2.6
FreeBSD FreeBSD 2.2.5
FreeBSD FreeBSD 2.2.4
FreeBSD FreeBSD 2.2.3
FreeBSD FreeBSD 2.2.2
FreeBSD FreeBSD 2.1.7 .1
Debian Linux 2.0
Debian Linux 1.3.1
Debian Linux 1.3
Debian Linux 1.2
BSDI BSD/OS 4.0
BSDI BSD/OS 3.0

Exploit / POC

Multiple Vendor talkd(8) Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Multiple Vendor talkd(8) Vulnerability

Solution:
BSDI
--------
Patches are available at:
ftp://ftp.bsdi.com/bsdi/patches/patches-2.1/U210-035

FreeBSD
------------
Patches are available at:
ftp://freebsd.org/pub/CERT/patches/SA-96:21

Hewlett Packard (HP-UX)
----------------------------------

Patches for this problem are available via the HP Online Support Center. Please see the URL in the Credit/Referance section.

IBM Corporation (AIX)
-----------------------------

AIX 3.2: APAR IX65474
AIX 4.1: APAR IX65472
AIX 4.2: APAR IX65473

APARs may be ordered using Electronic Fix Distribution (via FixDist) orfrom the IBM Support Center. For more information on FixDist.Please see the URL in the Credit/Referance section.

Silicon Graphics
-----------------------

The SGI anonymous FTP site is sgigate.sgi.com (204.94.209.1) or its
mirror, ftp.sgi.com. Security information and patches can be found
in the ~ftp/security and ~ftp/patches directories, respectfully.

The actual patch will be a tar file containing the following files:

Filename: README.patch.2132
Algorithm #1 (sum -r): 58795 8 README.patch.2132
Algorithm #2 (sum): 22126 8 README.patch.2132
MD5 checksum: 1C16F01A682CC8DB605DEC4C515B3ADD

Filename: patchSG0002132
Algorithm #1 (sum -r): 39922 1 patchSG0002132
Algorithm #2 (sum): 24988 1 patchSG0002132
MD5 checksum: 1BD1683D23D164F954BEE893B3CF8B2F

Filename: patchSG0002132.eoe2_sw
Algorithm #1 (sum -r): 29839 26 patchSG0002132.eoe2_sw
Algorithm #2 (sum): 636 26 patchSG0002132.eoe2_sw
MD5 checksum: EDB8C15F7D22F7104770D591952346E7

Filename: patchSG0002132.idb
Algorithm #1 (sum -r): 54227 1 patchSG0002132.idb
Algorithm #2 (sum): 34895 1 patchSG0002132.idb
MD5 checksum: 82E411637E20CB15E9EEFA3BA330F93D

Filename: README.patch.2133
Algorithm #1 (sum -r): 53634 8 README.patch.2133
Algorithm #2 (sum): 26859 8 README.patch.2133
MD5 checksum: 20FE236BEAC79EC8614BE84B5E291841

Filename: patchSG0002133
Algorithm #1 (sum -r): 05188 1 patchSG0002133
Algorithm #2 (sum): 27188 1 patchSG0002133
MD5 checksum: A4E881E9682DA41DE8897DE71D2EE42C

Filename: patchSG0002133.eoe_sw
Algorithm #1 (sum -r): 24652 27 patchSG0002133.eoe_sw
Algorithm #2 (sum): 6068 27 patchSG0002133.eoe_sw
MD5 checksum: 7ECC472AFE5105D195BCC2B75834D666

Filename: patchSG0002133.idb
Algorithm #1 (sum -r): 45369 1 patchSG0002133.idb
Algorithm #2 (sum): 35211 1 patchSG0002133.idb
MD5 checksum: 5BE2481FB3F325399BEE961AF0FB476C

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report