xtell Trusted TTY Device Name Remote Vulnerability
BID:4194
Info
xtell Trusted TTY Device Name Remote Vulnerability
| Bugtraq ID: | 4194 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0333 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by "Spybreak" <[email protected]>. |
| Vulnerable: |
xtell xtell 2.6.1 xtell xtell 1.91.1 |
| Not Vulnerable: | |
Discussion
xtell Trusted TTY Device Name Remote Vulnerability
xtell is a simple network messaging program. It may be used to transmit terminal messages between users and machines. xtell is available for Linux, BSD and most other Unix based operating systems.
xtell accepts untrusted user input as the TTY device to write to. In addition to specifying arbitrary devices, it is possible to mount a '../' directory traversal against arbitrary files. The value supplied as a device name is restricted to eight characters.
It may also be possible to exhaust available disk space by specifying a mundane file instead of a device name.
Earlier versions of xtell may share this vulnerability. This has not been confirmed.
xtell is a simple network messaging program. It may be used to transmit terminal messages between users and machines. xtell is available for Linux, BSD and most other Unix based operating systems.
xtell accepts untrusted user input as the TTY device to write to. In addition to specifying arbitrary devices, it is possible to mount a '../' directory traversal against arbitrary files. The value supplied as a device name is restricted to eight characters.
It may also be possible to exhaust available disk space by specifying a mundane file instead of a device name.
Earlier versions of xtell may share this vulnerability. This has not been confirmed.
Exploit / POC
xtell Trusted TTY Device Name Remote Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
xtell Trusted TTY Device Name Remote Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
xtell xtell 1.91.1
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
xtell xtell 1.91.1
-
Debian xtell_1.91.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/xtel l_1.91.1_alpha.deb -
Debian xtell_1.91.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/xtell_ 1.91.1_arm.deb -
Debian xtell_1.91.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xtell _1.91.1_i386.deb -
Debian xtell_1.91.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xtell _1.91.1_m68k.deb -
Debian xtell_1.91.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/xt ell_1.91.1_powerpc.deb -
Debian xtell_1.91.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/xtel l_1.91.1_sparc.deb