PT-2001-1014 · Netkit+4 · Telnet+12

Published

2001-04-17

·

Updated

2022-01-21

·

CVE-2001-0554

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5-workstation versions 1.1.1 through 1.2.2 krb5-devel versions 1.1.1 through 1.2.2 krb5-configs version 1.1.1 krb5-server versions 1.1.1 through 1.2.2 krb5-libs version 1.1.1 krb5 version 1.1.1 through 1.2.2 telnet version 0.17 telnet-server versions 0.17 through 0.17.6x-18 netkit-telnetd version 0.17-r3 and earlier ssltelnet (affected versions not specified)
Description The issue is related to multiple vulnerabilities in various packages of Red Hat Linux, Gentoo Linux, and Debian GNU/Linux operating systems. These vulnerabilities can be exploited remotely, leading to a breach of confidentiality, integrity, and availability of protected information. A buffer overflow in the BSD-based telnetd telnet daemon allows remote attackers to execute arbitrary commands via a set of options, including AYT (Are You There), which is not properly handled by the telrcv function.
Recommendations For krb5-workstation versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-devel versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-configs version 1.1.1, update to a version later than 1.1.1. For krb5-server versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-libs version 1.1.1, update to a version later than 1.1.1. For krb5 versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For telnet version 0.17, update to a version later than 0.17. For telnet-server versions 0.17 through 0.17.6x-18, update to a version later than 0.17.6x-18. For netkit-telnetd version 0.17-r3 and earlier, update to a version later than 0.17-r3. For ssltelnet, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03713
BDU:2015-07908
BDU:2015-07909
BDU:2015-07910
BDU:2015-07911
BDU:2015-08132
BDU:2015-08133
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08139
BDU:2015-08142
BDU:2015-08143
BDU:2015-08145
BDU:2015-08146
BDU:2015-09453
CVE-2001-0554

Affected Products

Debian
Gentoo Linux
Red Hat
Krb5
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation
Netkit-Telnet
Ssltelnet
Telnet
Telnet-Server