PT-2007-2324 · Oracle · Solaris
Published
2007-02-12
·
Updated
2026-01-23
·
CVE-2007-0882
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Solaris versions 10 and 11
Description:
The issue concerns an argument injection vulnerability in the telnet daemon, where certain client sequences are misinterpreted as valid requests to skip authentication. This allows remote attackers to log into specific accounts without proper authentication.
Recommendations:
For Solaris versions 10 and 11, consider disabling the telnet daemon until a patch is available to prevent exploitation of this issue. Restrict access to sensitive accounts, such as the bin account, to minimize the risk of unauthorized access.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solaris