FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
BID:33777
Info
FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
| Bugtraq ID: | 33777 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2009 12:00AM |
| Updated: | May 26 2009 07:00PM |
| Credit: | Kingcope Kingcope |
| Vulnerable: |
FreeBSD FreeBSD 7.1-STABLE FreeBSD FreeBSD 7.0-STABLE FreeBSD FreeBSD 7.0-RELEASE |
| Not Vulnerable: | |
Discussion
FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
FreeBSD is prone to a remote code-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will facilitate in the complete compromise of affected computers.
FreeBSD 7.0 and 7.1 branches are vulnerable.
FreeBSD is prone to a remote code-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will facilitate in the complete compromise of affected computers.
FreeBSD 7.0 and 7.1 branches are vulnerable.
Exploit / POC
FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
FreeBSD FreeBSD 7.1-STABLE
FreeBSD FreeBSD 7.0-RELEASE
FreeBSD FreeBSD 7.0-STABLE
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
FreeBSD FreeBSD 7.1-STABLE
-
FreeBSD telnetd.patch
http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch
FreeBSD FreeBSD 7.0-RELEASE
-
FreeBSD telnetd.patch
http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch
FreeBSD FreeBSD 7.0-STABLE
-
FreeBSD telnetd.patch
http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch
References
FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- telnetd code execution vulnerability (FreeBSD)