RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerability
BID:5531
Info
RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerability
| Bugtraq ID: | 5531 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2002 12:00AM |
| Updated: | Feb 01 2008 08:17PM |
| Credit: | Mentioned in Sun patch notes. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.8 Sun Solaris 2.7_sparc Sun Solaris 2.7 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 Sun Solaris 2.4_x86 Sun Solaris 2.4 Sun Solaris 2.3 Sun Solaris 2.2 Sun Solaris 2.1 Sun Solaris 2.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerability
The telnet server shipped with Sun Microsystem's Solaris operating system is vulnerable to a buffer-overflow condition. Remote attackers may exploit this vulnerability to gain root access on target hosts.
**RETRACTION NOTE: It has been determined that this report was sent out in error and that the listed patches likely correct BID 3064 ("Multiple Vendor Telnetd Buffer Overflow Vulnerability"). This alert was originally published after the discovery of functional exploit code that appeared to exploit telnetd. It has since been determined that the code, an exploit for BID 3681 ("Multiple Vendor System V Derived 'login' Buffer Overflow Vulnerability"), was leaked from Internet Security Systems. It has been removed from the SecurityFocus archives. This BID will be retired.
The telnet server shipped with Sun Microsystem's Solaris operating system is vulnerable to a buffer-overflow condition. Remote attackers may exploit this vulnerability to gain root access on target hosts.
**RETRACTION NOTE: It has been determined that this report was sent out in error and that the listed patches likely correct BID 3064 ("Multiple Vendor Telnetd Buffer Overflow Vulnerability"). This alert was originally published after the discovery of functional exploit code that appeared to exploit telnetd. It has since been determined that the code, an exploit for BID 3681 ("Multiple Vendor System V Derived 'login' Buffer Overflow Vulnerability"), was leaked from Internet Security Systems. It has been removed from the SecurityFocus archives. This BID will be retired.
Solution / Fix
RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerability
Solution:
Sun has provided patches.
Sun Solaris 7.0
Sun Solaris 7.0_x86
Sun Solaris 8_x86
Sun Solaris 2.6
Sun Solaris 8_sparc
Sun Solaris 2.6_x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _x86
Solution:
Sun has provided patches.
Sun Solaris 7.0
-
Sun 107475-04
http://sunsolve.sun.com
Sun Solaris 7.0_x86
-
Sun 107476-04
http://sunsolve.sun.com
Sun Solaris 8_x86
-
Sun 110669-03
http://sunsolve.sun.com
Sun Solaris 2.6
-
Sun 106049-04
http://sunsolve.sun.com
Sun Solaris 8_sparc
-
Sun 110668-03
http://sunsolve.sun.com
Sun Solaris 2.6_x86
-
Sun 106050-04
http://sunsolve.sun.com
Sun Solaris 2.5.1
-
Sun 103640-40
http://sunsolve.sun.com
Sun Solaris 2.5.1 _x86
-
Sun 103641-40
http://sunsolve.sun.com