Pragma InterAccess Denial of Service Vulnerability
BID:2834
Info
Pragma InterAccess Denial of Service Vulnerability
| Bugtraq ID: | 2834 |
| Class: | Unknown |
| CVE: |
CVE-2001-1263 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2001 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | This vulnerability was posted to BugTraq on June 6th, 2001 by <[email protected]>. |
| Vulnerable: |
Pragma Systems InterAccess TelnetD Server 4.0 Build 5 Pragma Systems InterAccess TelnetD Server 4.0 Build 4 Pragma Systems InterAccess TelnetD Server 4.0 |
| Not Vulnerable: |
Pragma Systems InterAccess TelnetD Server 4.0 Build 8 Pragma Systems InterAccess TelnetD Server 4.0 Build 7 Pragma Systems InterAccess TelnetD Server 4.0 Build 6 |
Discussion
Pragma InterAccess Denial of Service Vulnerability
Pragma InterAccess for Microsoft 95/98 is a fully-featured commercial Telnet server.
Pragma InterAccess does not adequately compensate for large bursts of data being sent to port 23(telnet). If an excessive amount of characters(15000+) are sent to this port then the program will terminate and telnet services will shut down on that host. The daemon must be restarted to regain functionality.
This may be due to a buffer overflow condition. If this is the case, it may be possible for attackers to execute arbitrary code on the target host.
Pragma InterAccess for Microsoft 95/98 is a fully-featured commercial Telnet server.
Pragma InterAccess does not adequately compensate for large bursts of data being sent to port 23(telnet). If an excessive amount of characters(15000+) are sent to this port then the program will terminate and telnet services will shut down on that host. The daemon must be restarted to regain functionality.
This may be due to a buffer overflow condition. If this is the case, it may be possible for attackers to execute arbitrary code on the target host.
Exploit / POC
Pragma InterAccess Denial of Service Vulnerability
<[email protected]> has created a script to exploit this vulnerability.
<[email protected]> has created a script to exploit this vulnerability.
Solution / Fix
Pragma InterAccess Denial of Service Vulnerability
Solution:
The vendor has repaired the issue in newer versions of the software.
Pragma Systems InterAccess TelnetD Server 4.0
Pragma Systems InterAccess TelnetD Server 4.0 Build 4
Pragma Systems InterAccess TelnetD Server 4.0 Build 5
Solution:
The vendor has repaired the issue in newer versions of the software.
Pragma Systems InterAccess TelnetD Server 4.0
-
Pragma Systems InterAccess Release 4 Build 6
http://www.pragmasys.com/Downloads.html
Pragma Systems InterAccess TelnetD Server 4.0 Build 4
-
Pragma Systems InterAccess Release 4 Build 6
http://www.pragmasys.com/Downloads.html
Pragma Systems InterAccess TelnetD Server 4.0 Build 5
-
Pragma Systems InterAccess Release 4 Build 6
http://www.pragmasys.com/Downloads.html
References
Pragma InterAccess Denial of Service Vulnerability
References:
References:
- DHCorp Advisories (DHCorp)
- InterAccess for Win 95/98 Product Page (Pragma Systems)