Multiple Vendor talkd(8) Vulnerability
BID:210
Info
Multiple Vendor talkd(8) Vulnerability
| Bugtraq ID: | 210 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 18 1997 12:00AM |
| Updated: | Jan 18 1997 12:00AM |
| Credit: | This bug was initially posted to Comp.Security.Unix in July of 1997 by an anonymous poster. It was later followed by multiple vendor and FIRST agency advisories. |
| Vulnerable: |
SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 XFS SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 SGI IRIX 4.0.5 IPR SGI IRIX 4.0.5 H SGI IRIX 4.0.5 G SGI IRIX 4.0.5 F SGI IRIX 4.0.5 E SGI IRIX 4.0.5 D SGI IRIX 4.0.5 A SGI IRIX 4.0.5 (IOP) SGI IRIX 4.0.5 SGI IRIX 4.0.4 T SGI IRIX 4.0.4 B SGI IRIX 4.0.4 SGI IRIX 4.0.3 SGI IRIX 4.0.2 SGI IRIX 4.0.1 SGI IRIX 4.0 Redhat Linux 3.0.3 Redhat Linux 2.1 Redhat Linux 2.0 NEC UX/4800 (64) NEC UP-UX/V (Rel4.2MP) NEC Ews-Ux V (Rel4.2MP) NEC Ews-Ux V (Rel4.2) IBM AIX 4.2 IBM AIX 4.1 IBM AIX 3.2 HP HP-UX (VVOS) 10.24 HP HP-UX 10.34 HP HP-UX 10.30 HP HP-UX 10.20 HP HP-UX 10.16 HP HP-UX 10.10 HP HP-UX 10.9 HP HP-UX 10.8 HP HP-UX 10.1 0 HP HP-UX 10.0 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 Debian Linux 1.1 Debian Linux 0.93 BSDI BSD/OS 2.1 BSDI BSD/OS 2.0.1 BSDI BSD/OS 2.0 BSDI BSD/OS 1.1 |
| Not Vulnerable: |
SGI IRIX 6.5 Redhat Linux 5.2 i386 Redhat Linux 5.1 Redhat Linux 5.0 Redhat Linux 4.2 Redhat Linux 4.1 Redhat Linux 4.0 IBM AIX 4.3 IBM AIX 4.2.1 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.1.7 .1 Debian Linux 2.0 Debian Linux 1.3.1 Debian Linux 1.3 Debian Linux 1.2 BSDI BSD/OS 4.0 BSDI BSD/OS 3.0 |
Exploit / POC
Multiple Vendor talkd(8) Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor talkd(8) Vulnerability
Solution:
BSDI
--------
Patches are available at:
ftp://ftp.bsdi.com/bsdi/patches/patches-2.1/U210-035
FreeBSD
------------
Patches are available at:
ftp://freebsd.org/pub/CERT/patches/SA-96:21
Hewlett Packard (HP-UX)
----------------------------------
Patches for this problem are available via the HP Online Support Center. Please see the URL in the Credit/Referance section.
IBM Corporation (AIX)
-----------------------------
AIX 3.2: APAR IX65474
AIX 4.1: APAR IX65472
AIX 4.2: APAR IX65473
APARs may be ordered using Electronic Fix Distribution (via FixDist) orfrom the IBM Support Center. For more information on FixDist.Please see the URL in the Credit/Referance section.
Silicon Graphics
-----------------------
The SGI anonymous FTP site is sgigate.sgi.com (204.94.209.1) or its
mirror, ftp.sgi.com. Security information and patches can be found
in the ~ftp/security and ~ftp/patches directories, respectfully.
The actual patch will be a tar file containing the following files:
Filename: README.patch.2132
Algorithm #1 (sum -r): 58795 8 README.patch.2132
Algorithm #2 (sum): 22126 8 README.patch.2132
MD5 checksum: 1C16F01A682CC8DB605DEC4C515B3ADD
Filename: patchSG0002132
Algorithm #1 (sum -r): 39922 1 patchSG0002132
Algorithm #2 (sum): 24988 1 patchSG0002132
MD5 checksum: 1BD1683D23D164F954BEE893B3CF8B2F
Filename: patchSG0002132.eoe2_sw
Algorithm #1 (sum -r): 29839 26 patchSG0002132.eoe2_sw
Algorithm #2 (sum): 636 26 patchSG0002132.eoe2_sw
MD5 checksum: EDB8C15F7D22F7104770D591952346E7
Filename: patchSG0002132.idb
Algorithm #1 (sum -r): 54227 1 patchSG0002132.idb
Algorithm #2 (sum): 34895 1 patchSG0002132.idb
MD5 checksum: 82E411637E20CB15E9EEFA3BA330F93D
Filename: README.patch.2133
Algorithm #1 (sum -r): 53634 8 README.patch.2133
Algorithm #2 (sum): 26859 8 README.patch.2133
MD5 checksum: 20FE236BEAC79EC8614BE84B5E291841
Filename: patchSG0002133
Algorithm #1 (sum -r): 05188 1 patchSG0002133
Algorithm #2 (sum): 27188 1 patchSG0002133
MD5 checksum: A4E881E9682DA41DE8897DE71D2EE42C
Filename: patchSG0002133.eoe_sw
Algorithm #1 (sum -r): 24652 27 patchSG0002133.eoe_sw
Algorithm #2 (sum): 6068 27 patchSG0002133.eoe_sw
MD5 checksum: 7ECC472AFE5105D195BCC2B75834D666
Filename: patchSG0002133.idb
Algorithm #1 (sum -r): 45369 1 patchSG0002133.idb
Algorithm #2 (sum): 35211 1 patchSG0002133.idb
MD5 checksum: 5BE2481FB3F325399BEE961AF0FB476C
Solution:
BSDI
--------
Patches are available at:
ftp://ftp.bsdi.com/bsdi/patches/patches-2.1/U210-035
FreeBSD
------------
Patches are available at:
ftp://freebsd.org/pub/CERT/patches/SA-96:21
Hewlett Packard (HP-UX)
----------------------------------
Patches for this problem are available via the HP Online Support Center. Please see the URL in the Credit/Referance section.
IBM Corporation (AIX)
-----------------------------
AIX 3.2: APAR IX65474
AIX 4.1: APAR IX65472
AIX 4.2: APAR IX65473
APARs may be ordered using Electronic Fix Distribution (via FixDist) orfrom the IBM Support Center. For more information on FixDist.Please see the URL in the Credit/Referance section.
Silicon Graphics
-----------------------
The SGI anonymous FTP site is sgigate.sgi.com (204.94.209.1) or its
mirror, ftp.sgi.com. Security information and patches can be found
in the ~ftp/security and ~ftp/patches directories, respectfully.
The actual patch will be a tar file containing the following files:
Filename: README.patch.2132
Algorithm #1 (sum -r): 58795 8 README.patch.2132
Algorithm #2 (sum): 22126 8 README.patch.2132
MD5 checksum: 1C16F01A682CC8DB605DEC4C515B3ADD
Filename: patchSG0002132
Algorithm #1 (sum -r): 39922 1 patchSG0002132
Algorithm #2 (sum): 24988 1 patchSG0002132
MD5 checksum: 1BD1683D23D164F954BEE893B3CF8B2F
Filename: patchSG0002132.eoe2_sw
Algorithm #1 (sum -r): 29839 26 patchSG0002132.eoe2_sw
Algorithm #2 (sum): 636 26 patchSG0002132.eoe2_sw
MD5 checksum: EDB8C15F7D22F7104770D591952346E7
Filename: patchSG0002132.idb
Algorithm #1 (sum -r): 54227 1 patchSG0002132.idb
Algorithm #2 (sum): 34895 1 patchSG0002132.idb
MD5 checksum: 82E411637E20CB15E9EEFA3BA330F93D
Filename: README.patch.2133
Algorithm #1 (sum -r): 53634 8 README.patch.2133
Algorithm #2 (sum): 26859 8 README.patch.2133
MD5 checksum: 20FE236BEAC79EC8614BE84B5E291841
Filename: patchSG0002133
Algorithm #1 (sum -r): 05188 1 patchSG0002133
Algorithm #2 (sum): 27188 1 patchSG0002133
MD5 checksum: A4E881E9682DA41DE8897DE71D2EE42C
Filename: patchSG0002133.eoe_sw
Algorithm #1 (sum -r): 24652 27 patchSG0002133.eoe_sw
Algorithm #2 (sum): 6068 27 patchSG0002133.eoe_sw
MD5 checksum: 7ECC472AFE5105D195BCC2B75834D666
Filename: patchSG0002133.idb
Algorithm #1 (sum -r): 45369 1 patchSG0002133.idb
Algorithm #2 (sum): 35211 1 patchSG0002133.idb
MD5 checksum: 5BE2481FB3F325399BEE961AF0FB476C