Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

TELNET:EXPLOIT:SUN-TELNETD-OF

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

TELNET

Keywords

Solaris Telnetd "TTYPROMPT" Buffer Overflow

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

TELNET: Solaris Telnetd "TTYPROMPT" Buffer Overflow


This signature detects attempts to exploit a known vulnerability against the TELNET daemon that ships with Solaris 8 and earlier. A successful attacker can cause a buffer overflow and remotely gain root access.

Extended Description

The 'login' program is used in UNIX systems to authenticate users with a username and password. The utility is typically invoked at the console, by 'telnetd', 'rlogind', and if configured to do so, SSH. Versions of 'login' descended from System V UNIX contain a buffer overflow when handling environment variables. Several operating systems such as Solaris/SunOS, HP-UX, AIX, IRIX, and Unixware contain vulnerable versions of 'login'. Unauthenticated clients can exploit this issue to execute arbitrary code as root. On systems where 'login' is installed setuid root, local attackers can elevate privileges.

Affected Products

  • Cisco Billing and Management Server
  • Cisco PGW2200 PSTN Gateway
  • Cisco Secure IDS Network Sensor 3.0.0
  • Cisco Secure IDS Network Sensor 3.0.0 (2)S6
  • Cisco Signaling Controller 2200
  • Cisco Voice Services Provisioning Tool
  • HP HP-UX 10.0.0
  • HP HP-UX 10.0.0 1
  • HP HP-UX 10.10.0
  • HP HP-UX 10.20.0
  • HP HP-UX 11.0.0
  • HP HP-UX 11.11.0
  • HP HP-UX (VVOS) 10.24.0
  • HP HP-UX (VVOS) 11.0.4
  • IBM AIX 4.3.0
  • IBM AIX 4.3.1
  • IBM AIX 4.3.2
  • IBM AIX 4.3.3
  • IBM AIX 5.1
  • SCO Open Server 5.0.0
  • SCO Open Server 5.0.1
  • SCO Open Server 5.0.2
  • SCO Open Server 5.0.3
  • SCO Open Server 5.0.4
  • SCO Open Server 5.0.5
  • SCO Open Server 5.0.6
  • SCO Open Server 5.0.6 a
  • SGI IRIX 3.2.0
  • SGI IRIX 3.3.0
  • SGI IRIX 3.3.1
  • SGI IRIX 3.3.2
  • SGI IRIX 3.3.3
  • Sun Solaris 2.0
  • Sun Solaris 2.1
  • Sun Solaris 2.2
  • Sun Solaris 2.3
  • Sun Solaris 2.4
  • Sun Solaris 2.4_x86
  • Sun Solaris 2.5
  • Sun Solaris 2.5.1
  • Sun Solaris 2.5.1_ppc
  • Sun Solaris 2.5.1_x86
  • Sun Solaris 2.5_x86
  • Sun Solaris 2.6
  • Sun Solaris 2.6_x86
  • Sun Solaris 7.0
  • Sun Solaris 7.0_x86
  • Sun Solaris 8 Sparc
  • Sun Solaris 8 X86

References

  • BugTraq: 3681
  • BugTraq: 5531
  • CERT: CA-2001-34
  • CVE: CVE-2001-0797
  • URL: http://online.securityfocus.com/archive/1/288423/2002-08-19/2002-08-25/0

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out