Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

TELNET:OVERFLOW:NEW-ENVIRON-OF

Severity

High

Recommended

No

Recommended Action

Drop

Category

TELNET

Keywords

NEW-ENVIRON Overflow

Release Date

2005/04/04

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

TELNET: NEW-ENVIRON Overflow


This signature detects attempts to exploit a known vulnerability in telnet clients. The env_opt_add function of some telnet clients incorrectly handles NEWENVIRON sub-options. Attackers can send a maliciously crafted SEND command to a telnet client to overflow the buffer, then execute arbitrary code on the target system with the telnet client account privileges.

Extended Description

Multiple vendors' Telnet client applications are reported prone to a remote buffer-overflow vulnerability. This vulnerability reportedly occurs in the 'env_opt_add()' function in the 'telnet.c' source file, which is apparently common source for all the affected vendors. A remote attacker may exploit this vulnerability to execute arbitrary code on some of the affected platforms in the context of a user that is using the vulnerable Telnet client to connect to a malicious server.

Affected Products

  • ALT Linux ALT Linux Compact 2.3.0
  • ALT Linux ALT Linux Junior 2.3.0
  • Apple Mac OS X 10.0.0
  • Apple Mac OS X 10.0.0 3
  • Apple Mac OS X 10.0.1
  • Apple Mac OS X 10.0.2
  • Apple Mac OS X 10.0.3
  • Apple Mac OS X 10.0.4
  • Apple Mac OS X 10.1.0
  • Apple Mac OS X 10.1.1
  • Apple Mac OS X 10.1.2
  • Apple Mac OS X 10.1.3
  • Apple Mac OS X 10.1.4
  • Apple Mac OS X 10.1.5
  • Apple Mac OS X 10.2.0
  • Apple Mac OS X 10.2.1
  • Apple Mac OS X 10.2.2
  • Apple Mac OS X 10.2.3
  • Apple Mac OS X 10.2.4
  • Apple Mac OS X 10.2.5
  • Apple Mac OS X 10.2.6
  • Apple Mac OS X 10.2.7
  • Apple Mac OS X 10.2.8
  • Apple Mac OS X 10.3.0
  • Apple Mac OS X 10.3.1
  • Apple Mac OS X 10.3.2
  • Apple Mac OS X 10.3.3
  • Apple Mac OS X 10.3.4
  • Apple Mac OS X 10.3.5
  • Apple Mac OS X 10.3.6
  • Apple Mac OS X 10.3.7
  • Apple Mac OS X 10.3.8
  • Apple Mac OS X Server 10.0.0
  • Apple Mac OS X Server 10.1.0
  • Apple Mac OS X Server 10.1.1
  • Apple Mac OS X Server 10.1.2
  • Apple Mac OS X Server 10.1.3
  • Apple Mac OS X Server 10.1.4
  • Apple Mac OS X Server 10.1.5
  • Apple Mac OS X Server 10.2.0
  • Apple Mac OS X Server 10.2.1
  • Apple Mac OS X Server 10.2.2
  • Apple Mac OS X Server 10.2.3
  • Apple Mac OS X Server 10.2.4
  • Apple Mac OS X Server 10.2.5
  • Apple Mac OS X Server 10.2.6
  • Apple Mac OS X Server 10.2.7
  • Apple Mac OS X Server 10.2.8
  • Apple Mac OS X Server 10.3.0
  • Apple Mac OS X Server 10.3.1
  • Apple Mac OS X Server 10.3.2
  • Apple Mac OS X Server 10.3.3
  • Apple Mac OS X Server 10.3.4
  • Apple Mac OS X Server 10.3.5
  • Apple Mac OS X Server 10.3.6
  • Apple Mac OS X Server 10.3.7
  • Apple Mac OS X Server 10.3.8
  • Avaya Converged Communications Server 2.0.0
  • Avaya CVLAN
  • Avaya Intuity LX
  • Avaya MN100
  • Avaya Modular Messaging S3400
  • Avaya Modular Messaging (MSS) 1.1.0
  • Avaya Modular Messaging (MSS) 2.0.0
  • Avaya S8300 R2.0.0
  • Avaya S8300 R2.0.1
  • Avaya S8500 R2.0.0
  • Avaya S8500 R2.0.1
  • Avaya S8700 R2.0.0
  • Avaya S8700 R2.0.1
  • Avaya S8710 R2.0.0
  • Avaya S8710 R2.0.1
  • Conectiva Linux 10.0.0
  • Conectiva Linux 9.0.0
  • Debian Linux 3.0.0 Alpha
  • Debian Linux 3.0.0 Arm
  • Debian Linux 3.0.0 Hppa
  • Debian Linux 3.0.0 Ia-32
  • Debian Linux 3.0.0 Ia-64
  • Debian Linux 3.0.0 M68k
  • Debian Linux 3.0.0 Mips
  • Debian Linux 3.0.0 Mipsel
  • Debian Linux 3.0.0 Ppc
  • Debian Linux 3.0.0 S/390
  • Debian Linux 3.0.0 Sparc
  • F5 3-DNS 4.2.0
  • F5 3-DNS 4.3.0
  • F5 3-DNS 4.4.0
  • F5 3-DNS 4.5.0
  • F5 3-DNS 4.5.11
  • F5 3-DNS 4.5.12
  • F5 3-DNS 4.6.0
  • F5 3-DNS 4.6.2
  • F5 BigIP 4.0.0
  • F5 BigIP 4.2.0
  • F5 BigIP 4.3.0
  • F5 BigIP 4.4.0
  • F5 BigIP 4.5.0
  • F5 BigIP 4.5.10
  • F5 BigIP 4.5.11
  • F5 BigIP 4.5.12
  • F5 BigIP 4.5.6
  • F5 BigIP 4.5.9
  • F5 BigIP 4.6.0
  • F5 BigIP 4.6.2
  • FreeBSD 4.0.0
  • FreeBSD 4.0.0 Alpha
  • FreeBSD 4.0.0 -RELENG
  • FreeBSD 4.0.0 .X
  • FreeBSD 4.1.0
  • FreeBSD 4.10.0
  • FreeBSD 4.10.0 -RELEASE
  • FreeBSD 4.10.0 -RELENG
  • FreeBSD 4.1.1
  • FreeBSD 4.11.0 -STABLE
  • FreeBSD 4.1.1 -RELEASE
  • FreeBSD 4.1.1 -STABLE
  • FreeBSD 4.2.0
  • FreeBSD 4.2.0 -RELEASE
  • FreeBSD 4.2.0 -STABLE
  • FreeBSD 4.2.0 -Stablepre050201
  • FreeBSD 4.2.0 -Stablepre122300
  • FreeBSD 4.3.0
  • FreeBSD 4.3.0 -RELEASE
  • FreeBSD 4.3.0 -RELEASE-P38
  • FreeBSD 4.3.0 -RELENG
  • FreeBSD 4.3.0 -STABLE
  • FreeBSD 4.4.0
  • FreeBSD 4.4.0 -RELEASE-P42
  • FreeBSD 4.4.0 -RELENG
  • FreeBSD 4.4.0 -STABLE
  • FreeBSD 4.5.0
  • FreeBSD 4.5.0 -RELEASE
  • FreeBSD 4.5.0 -RELEASE-P32
  • FreeBSD 4.5.0 -RELENG
  • FreeBSD 4.5.0 -STABLE
  • FreeBSD 4.5.0 -Stablepre2002-03-07
  • FreeBSD 4.6.0
  • FreeBSD 4.6.0 -RELEASE
  • FreeBSD 4.6.0 -RELEASE-P20
  • FreeBSD 4.6.0 -RELENG
  • FreeBSD 4.6.0 -STABLE
  • FreeBSD 4.6.2
  • FreeBSD 4.7.0
  • FreeBSD 4.7.0 -RELEASE
  • FreeBSD 4.7.0 -RELEASE-P17
  • FreeBSD 4.7.0 -RELENG
  • FreeBSD 4.7.0 -STABLE
  • FreeBSD 4.8.0
  • FreeBSD 4.8.0 -PRERELEASE
  • FreeBSD 4.8.0 -RELEASE-P7
  • FreeBSD 4.8.0 -RELENG
  • FreeBSD 4.9.0
  • FreeBSD 4.9.0 -PRERELEASE
  • FreeBSD 4.9.0 -RELENG
  • FreeBSD 5.0.0
  • FreeBSD 5.0.0 Alpha
  • FreeBSD 5.0.0 -RELEASE-P14
  • FreeBSD 5.0.0 -RELENG
  • FreeBSD 5.1.0
  • FreeBSD 5.1.0 -RELEASE
  • FreeBSD 5.1.0 -RELEASE/Alpha
  • FreeBSD 5.1.0 -RELEASE-P5
  • FreeBSD 5.1.0 -RELENG
  • FreeBSD 5.2.0
  • FreeBSD 5.2.0 -RELEASE
  • FreeBSD 5.2.0 -RELENG
  • FreeBSD 5.2.1 -RELEASE
  • FreeBSD 5.3.0
  • FreeBSD 5.3.0 -RELEASE
  • FreeBSD 5.3.0 -STABLE
  • FreeBSD 5.4.0 -PRERELEASE
  • Gentoo Linux
  • Heimdal 0.5.0 .0
  • Heimdal 0.5.1
  • Heimdal 0.5.2
  • Heimdal 0.5.3
  • Heimdal 0.6.0
  • Heimdal 0.6.1
  • Heimdal 0.6.2
  • Heimdal 0.6.3
  • MIT Kerberos 5 1.0.0
  • MIT Kerberos 5 1.0.6
  • MIT Kerberos 5 1.0.8
  • MIT Kerberos 5 1.1.0
  • MIT Kerberos 5 1.1.1
  • MIT Kerberos 5 1.2.0
  • MIT Kerberos 5 1.2.1
  • MIT Kerberos 5 1.2.2
  • MIT Kerberos 5 1.2.2 -Beta1
  • MIT Kerberos 5 1.2.3
  • MIT Kerberos 5 1.2.4
  • MIT Kerberos 5 1.2.5
  • MIT Kerberos 5 1.2.6
  • MIT Kerberos 5 1.2.7
  • MIT Kerberos 5 1.2.8
  • MIT Kerberos 5 1.3.0
  • MIT Kerberos 5 1.3.0 -Alpha1
  • MIT Kerberos 5 1.3.1
  • MIT Kerberos 5 1.3.2
  • MIT Kerberos 5 1.3.3
  • MIT Kerberos 5 1.3.4
  • MIT Kerberos 5 1.3.5
  • MIT Kerberos 5 1.3.6
  • MIT Kerberos 5 1.4.0
  • NetBSD 2.0.0
  • NetBSD 2.0.1
  • NetBSD 2.0.2
  • Netkit Linux Netkit 0.10.0
  • Netkit Linux Netkit 0.11.0
  • Netkit Linux Netkit 0.12.0
  • Netkit Linux Netkit 0.14.0
  • Netkit Linux Netkit 0.15.0
  • Netkit Linux Netkit 0.16.0
  • Netkit Linux Netkit 0.17.0
  • Netkit Linux Netkit 0.17.17
  • Netkit Linux Netkit 0.9.0
  • OpenBSD 3.5
  • OpenBSD 3.6
  • Openwall Openwall GNU/*/Linux 1.0.0
  • Openwall Openwall GNU/*/Linux 1.1.0
  • Openwall Openwall GNU/*/Linux (Owl)-Current
  • Red Hat Advanced Workstation for the Itanium Processor 2.1.0
  • Red Hat Advanced Workstation for the Itanium Processor 2.1.0 IA64
  • Red Hat Fedora Core1
  • Red Hat Linux 7.3.0
  • Red Hat Linux 7.3.0 I386
  • Red Hat Linux 7.3.0 I686
  • Red Hat Linux 9.0.0 I386
  • SCO Open Server 5.0.6
  • SCO Open Server 5.0.7
  • SCO Unixware 7.1.1
  • SCO Unixware 7.1.3
  • SCO Unixware 7.1.4
  • SGI IRIX 3.2.0
  • SGI IRIX 3.3.0
  • SGI IRIX 3.3.1
  • SGI IRIX 3.3.2
  • SGI IRIX 3.3.3
  • SGI IRIX 4.0.0
  • SGI IRIX 4.0.1
  • SGI IRIX 4.0.1 T
  • SGI IRIX 4.0.2
  • SGI IRIX 4.0.3
  • SGI IRIX 4.0.4
  • SGI IRIX 4.0.4 B
  • SGI IRIX 4.0.4 T
  • SGI IRIX 4.0.5
  • SGI IRIX 4.0.5 A
  • SGI IRIX 4.0.5 D
  • SGI IRIX 4.0.5 E
  • SGI IRIX 4.0.5 F
  • SGI IRIX 4.0.5 G
  • SGI IRIX 4.0.5 H
  • SGI IRIX 4.0.5 (IOP)
  • SGI IRIX 4.0.5 IPR
  • SGI IRIX 5.0.0
  • SGI IRIX 5.0.1
  • SGI IRIX 5.1.0
  • SGI IRIX 5.1.1
  • SGI IRIX 5.2.0
  • SGI IRIX 5.3.0
  • SGI IRIX 5.3.0 XFS
  • SGI IRIX 6.0.0
  • SGI IRIX 6.0.1
  • SGI IRIX 6.0.1 XFS
  • SGI IRIX 6.1.0
  • SGI IRIX 6.2.0
  • SGI IRIX 6.3.0
  • SGI IRIX 6.4.0
  • SGI IRIX 6.5.0
  • SGI IRIX 6.5.0 .19f
  • SGI IRIX 6.5.0 .19m
  • SGI IRIX 6.5.0 20
  • SGI IRIX 6.5.1
  • SGI IRIX 6.5.10
  • SGI IRIX 6.5.10 f
  • SGI IRIX 6.5.10 m
  • SGI IRIX 6.5.11
  • SGI IRIX 6.5.11 f
  • SGI IRIX 6.5.11 m
  • SGI IRIX 6.5.12
  • SGI IRIX 6.5.12 f
  • SGI IRIX 6.5.12 m
  • SGI IRIX 6.5.13
  • SGI IRIX 6.5.13 f
  • SGI IRIX 6.5.13 m
  • SGI IRIX 6.5.14
  • SGI IRIX 6.5.14 f
  • SGI IRIX 6.5.14 m
  • SGI IRIX 6.5.15
  • SGI IRIX 6.5.15 f
  • SGI IRIX 6.5.15 m
  • SGI IRIX 6.5.16
  • SGI IRIX 6.5.16 f
  • SGI IRIX 6.5.16 m
  • SGI IRIX 6.5.17
  • SGI IRIX 6.5.17 f
  • SGI IRIX 6.5.17 m
  • SGI IRIX 6.5.18
  • SGI IRIX 6.5.18 f
  • SGI IRIX 6.5.18 m
  • SGI IRIX 6.5.19
  • SGI IRIX 6.5.19 F
  • SGI IRIX 6.5.19 M
  • SGI IRIX 6.5.2
  • SGI IRIX 6.5.20
  • SGI IRIX 6.5.20 F
  • SGI IRIX 6.5.20 M
  • SGI IRIX 6.5.21
  • SGI IRIX 6.5.21 F
  • SGI IRIX 6.5.21 M
  • SGI IRIX 6.5.22
  • SGI IRIX 6.5.22 m
  • SGI IRIX 6.5.23
  • SGI IRIX 6.5.23 M
  • SGI IRIX 6.5.24
  • SGI IRIX 6.5.24 M
  • SGI IRIX 6.5.25
  • SGI IRIX 6.5.26
  • SGI IRIX 6.5.27
  • SGI IRIX 6.5.2 f
  • SGI IRIX 6.5.2 m
  • SGI IRIX 6.5.3
  • SGI IRIX 6.5.3 f
  • SGI IRIX 6.5.3 m
  • SGI IRIX 6.5.4
  • SGI IRIX 6.5.4 f
  • SGI IRIX 6.5.4 m
  • SGI IRIX 6.5.5
  • SGI IRIX 6.5.5 f
  • SGI IRIX 6.5.5 m
  • SGI IRIX 6.5.6
  • SGI IRIX 6.5.6 f
  • SGI IRIX 6.5.6 m
  • SGI IRIX 6.5.7
  • SGI IRIX 6.5.7 f
  • SGI IRIX 6.5.7 m
  • SGI IRIX 6.5.8
  • SGI IRIX 6.5.8 f
  • SGI IRIX 6.5.8 m
  • SGI IRIX 6.5.9
  • SGI IRIX 6.5.9 f
  • SGI IRIX 6.5.9 m
  • SGI ProPack 3.0.0
  • Sun SEAM 1.0.0
  • Sun SEAM 1.0.1
  • Sun SEAM 1.0.2
  • SuSE Linux 7.0.0
  • SuSE Linux 7.0.0 Alpha
  • SuSE Linux 7.0.0 i386
  • SuSE Linux 7.0.0 ppc
  • SuSE Linux 7.0.0 sparc
  • SuSE Linux 7.1.0
  • SuSE Linux 7.1.0 Alpha
  • SuSE Linux 7.1.0 ppc
  • SuSE Linux 7.1.0 sparc
  • SuSE Linux 7.1.0 x86
  • SuSE Linux 7.2.0
  • SuSE Linux 7.2.0 i386
  • SuSE Linux 7.3.0
  • SuSE Linux 7.3.0 i386
  • SuSE Linux 7.3.0 ppc
  • SuSE Linux 7.3.0 sparc
  • SuSE Linux 8.0.0
  • SuSE Linux 8.0.0 i386
  • SuSE Linux 8.1.0
  • SuSE Linux Desktop 1.0.0
  • SuSE Linux Enterprise Server for S/390 9.0.0
  • SuSE Linux Personal 8.2.0
  • SuSE Linux Personal 9.0.0
  • SuSE Linux Personal 9.0.0 X86 64
  • SuSE Linux Personal 9.1.0
  • SuSE Linux Personal 9.1.0 X86 64
  • SuSE Linux Personal 9.2.0
  • SuSE Linux Personal 9.2.0 X86 64
  • SuSE SUSE Linux Enterprise Server 7
  • SuSE SUSE Linux Enterprise Server 8
  • SuSE SUSE Linux Enterprise Server 9
  • Trustix Secure Enterprise Linux 2.0.0
  • Trustix Secure Linux 2.1.0
  • Trustix Secure Linux 2.2.0
  • Ubuntu Ubuntu Linux 5.0.0 4 Amd64
  • Ubuntu Ubuntu Linux 5.0.0 4 I386
  • Ubuntu Ubuntu Linux 5.0.0 4 Powerpc

References

  • BugTraq: 12919
  • CVE: CVE-2005-0468
  • URL: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt
  • URL: http://www.idefense.com/application/poi/display?id=221&type=vulnerabilities

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out