FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
BID:51182
Info
FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 51182 |
| Class: | Unknown |
| CVE: |
CVE-2011-4862 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2011 12:00AM |
| Updated: | Apr 13 2015 08:36PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
VMWare ESX 4.0 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP4 SuSE openSUSE 11.4 SuSE openSUSE 11.3 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. CORE 9 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6.0.z Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 MIT Kerberos 5 1.7.2 MIT Kerberos 5 1.7.1 MIT Kerberos 5 1.6.4 MIT Kerberos 5 1.6.3 MIT Kerberos 5 1.6.2 MIT Kerberos 5 1.6.1 MIT Kerberos 5 1.6 MIT Kerberos 5 1.5.5 MIT Kerberos 5 1.5.4 MIT Kerberos 5 1.5.3 MIT Kerberos 5 1.5.2 MIT Kerberos 5 1.5.1 MIT Kerberos 5 1.5 MIT Kerberos 5 1.4.3 MIT Kerberos 5 1.4.2 MIT Kerberos 5 1.4.1 MIT Kerberos 5 1.4 MIT Kerberos 5 1.3.6 MIT Kerberos 5 1.3.5 MIT Kerberos 5 1.3.4 MIT Kerberos 5 1.3.3 MIT Kerberos 5 1.3.2 MIT Kerberos 5 1.3.1 MIT Kerberos 5 1.3 -alpha1 MIT Kerberos 5 1.3 MIT Kerberos 5 1.2.8 MIT Kerberos 5 1.2.7 MIT Kerberos 5 1.2.6 MIT Kerberos 5 1.2.5 MIT Kerberos 5 1.2.4 MIT Kerberos 5 1.2.3 MIT Kerberos 5 1.2.2 -beta1 MIT Kerberos 5 1.2.2 MIT Kerberos 5 1.2.1 MIT Kerberos 5 1.2 MIT Kerberos 5 1.1.1 MIT Kerberos 5 1.1 MIT Kerberos 5 1.0.8 MIT Kerberos 5 1.0.6 MIT Kerberos 5 1.0 MIT Kerberos 5 1.7 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux FreeBSD Freebsd 9.0-STABLE FreeBSD Freebsd 9.0-RELEASE FreeBSD Freebsd 9.0-RC3 FreeBSD Freebsd 9.0-RC1 FreeBSD Freebsd 8.2-STABLE FreeBSD Freebsd 8.2-STABLE FreeBSD Freebsd 8.2-RELEASE-p2 FreeBSD Freebsd 8.2-RELEASE-p1 FreeBSD Freebsd 8.2 - RELEASE -p3 FreeBSD Freebsd 8.2 FreeBSD Freebsd 8.1-RELEASE-p5 FreeBSD Freebsd 8.1-RELEASE-p4 FreeBSD FreeBSD 8.1-RELEASE FreeBSD FreeBSD 8.1-PRERELEASE FreeBSD Freebsd 8.1 FreeBSD FreeBSD 8.0-STABLE FreeBSD FreeBSD 8.0-RELEASE FreeBSD Freebsd 7.4-STABLE FreeBSD Freebsd 7.4-RELEASE-p2 FreeBSD Freebsd 7.4 -RELEASE-p3 FreeBSD Freebsd 7.4 FreeBSD FreeBSD 7.3-STABLE FreeBSD Freebsd 7.3-RELEASE-p6 FreeBSD FreeBSD 7.3-RELEASE-p1 FreeBSD Freebsd 7.3 - RELEASE - p7 FreeBSD Freebsd 7.3 FreeBSD FreeBSD 7.2-STABLE FreeBSD FreeBSD 7.2-RELEASE-p4 FreeBSD FreeBSD 7.2-RELEASE-p1 FreeBSD FreeBSD 7.2-RC2 FreeBSD FreeBSD 7.2-PRERELEASE FreeBSD Freebsd 7.2 FreeBSD FreeBSD 7.1-STABLE FreeBSD FreeBSD 7.1-RELEASE-p6 FreeBSD FreeBSD 7.1-RELEASE-p5 FreeBSD FreeBSD 7.1-RELEASE-p4 FreeBSD FreeBSD 7.1 Rc1 FreeBSD FreeBSD 7.1 -RELEASE-p2 FreeBSD FreeBSD 7.1 -RELEASE-p1 FreeBSD FreeBSD 7.1 -PRE-RELEASE FreeBSD FreeBSD 7.1 FreeBSD FreeBSD 7.0-STABLE FreeBSD FreeBSD 7.0-RELEASE-p8 FreeBSD FreeBSD 7.0-RELEASE-p3 FreeBSD FreeBSD 7.0-RELEASE-p12 FreeBSD FreeBSD 7.0-RELEASE-p11 FreeBSD FreeBSD 7.0-RELEASE FreeBSD FreeBSD 7.0 BETA4 FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 -RELEASE-p9 FreeBSD FreeBSD 7.0 -PRERELEASE FreeBSD FreeBSD 7.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cisco IronPort Security Management Appliance 0 Cisco IronPort Email Security Appliance X-Series 7.0.1 Cisco IronPort Email Security Appliance X-Series 0 Cisco IronPort Email Security Appliance C-Series 7.0.1 Cisco IronPort Email Security Appliance C-Series 0 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.0 |
| Not Vulnerable: |
MIT Kerberos 5 1.8 Cisco IronPort Security Management Appliance 7.8 Cisco IronPort Email Security Appliance X-Series 7.6 Cisco IronPort Email Security Appliance C-Series 7.6 |
Discussion
FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
FreeBSD is prone to a remote buffer-overflow vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code with superuser privileges. Successfully exploiting this issue will completely compromise affected computers.
FreeBSD is prone to a remote buffer-overflow vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code with superuser privileges. Successfully exploiting this issue will completely compromise affected computers.
Exploit / POC
FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva heimdal-daemons-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-devel-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-devel-doc-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-ftp-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-ftpd-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-libs-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-login-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-rsh-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-rshd-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-server-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-telnet-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-telnetd-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva heimdal-workstation-1.2-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-appl-clients-1.0-0.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-appl-servers-1.0-0.4mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva netkit-telnet-0.17-4.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva netkit-telnet-server-0.17-4.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva krb5-appl-clients-1.0.2-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva krb5-appl-servers-1.0.2-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva netkit-telnet-0.17-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva netkit-telnet-server-0.17-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
FreeBSD 'telnetd' Daemon Remote Buffer Overflow Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- FreeBSD-SA-11:08.telnetd (FreeBSD)
- MITKRB5-SA-2011-008: (MIT)
- Security Advisory Critical: krb5-appl security update (Red Hat)
- VMSA-2012-0006 (VMWare)
- Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability (Cisco)
- Critical: krb5 security update (Red Hat)