Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
BID:9316
Info
Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
| Bugtraq ID: | 9316 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2003 12:00AM |
| Updated: | Dec 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Jordan Windows Telnet Server 1.2 Jordan Windows Telnet Server 1.0 |
| Not Vulnerable: | |
Discussion
Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
Jordan Windows Telnet Server has been reported prone to a remote buffer overrun vulnerability. The issue has been reported to present itself when a username of excessive length is supplied to the Telnet server. Due to a lack of bounds checking, when this username is copied into an insufficient reserved buffer in stack-based memory, data that exceeds the size of the buffer will overrun its bounds and corrupt adjacent memory. An attacker may exploit this condition to corrupt a saved instruction pointer for the vulnerable function.
Jordan Windows Telnet Server has been reported prone to a remote buffer overrun vulnerability. The issue has been reported to present itself when a username of excessive length is supplied to the Telnet server. Due to a lack of bounds checking, when this username is copied into an insufficient reserved buffer in stack-based memory, data that exceeds the size of the buffer will overrun its bounds and corrupt adjacent memory. An attacker may exploit this condition to corrupt a saved instruction pointer for the vulnerable function.
Exploit / POC
Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
The following proof of concept and exploits are available:
The following proof of concept and exploits are available:
Solution / Fix
Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Jordan Windows Telnet Server Username Stack Based Buffer Overrun Vulnerability
References:
References:
- Windows Telnet Server Homepage (Jordan)
- Buffer-overflow in Jordan's telnet server (Luigi Auriemma
)