Short Name |
TELNET:OVERFLOW:LINEMODE-OF |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
TELNET |
Keywords |
Buffer Overflow: LINEMODE |
Release Date |
2005/03/31 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in telnet client processing of the LINEMODE sub-options. Some telnet clients improperly handle replies with a large number of SLC commands; attackers can inject arbitrary code into the telnet process.
A remote buffer-overflow vulnerability affects multiple vendors' Telnet client. This issue is due to the application's failure to properly validate the length of user-supplied strings before copying them into static process buffers. An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.