Microsoft Telnet Server Buffer Overflow Vulnerability
BID:4061
Info
Microsoft Telnet Server Buffer Overflow Vulnerability
| Bugtraq ID: | 4061 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Feb 07 2002 12:00AM |
| Credit: | This vulnerability was reported by Microsoft in Security Bulletin MS02-004. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Interix 2.2 |
| Not Vulnerable: | |
Discussion
Microsoft Telnet Server Buffer Overflow Vulnerability
Microsoft Telnet Server provides remote shell accessibility to a system. The Telnet Service is available in Microsoft Windows 2000 and Microsoft Interix.
The Telnet Server contained in both these products is vulnerable to a buffer overflow in the code that handles the processing of telnet protocol options. Successful exploitation of this vulnerability will result in the Telnet Server failing. The buffer overflow could also potentially allow the execution of arbitrary code on the affected system.
Microsoft Telnet Server provides remote shell accessibility to a system. The Telnet Service is available in Microsoft Windows 2000 and Microsoft Interix.
The Telnet Server contained in both these products is vulnerable to a buffer overflow in the code that handles the processing of telnet protocol options. Successful exploitation of this vulnerability will result in the Telnet Server failing. The buffer overflow could also potentially allow the execution of arbitrary code on the affected system.
Exploit / POC
Microsoft Telnet Server Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Telnet Server Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch that addresses this vulnerability:
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP2
Microsoft Interix 2.2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server
Solution:
Microsoft has released a patch that addresses this vulnerability:
Microsoft Windows 2000 Professional
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Server SP2
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Interix 2.2
-
Microsoft in.telnetd
http://download.microsoft.com/download/winntunx/Patch/Q307298/NT5/EN-U S/in.telnetd
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Datacenter Server
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Server SP1
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Professional SP2
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Advanced Server
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Professional SP1
-
Microsoft Q307298
http://download.microsoft.com/download/win2000platform/Patch/q307298/N T5/EN-US/Q307298_W2K_SP3_x86_en.exe
Microsoft Windows 2000 Server