Back to search
CVE-2007-0882
Published: Feb 12, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20070212 Solaris telnet vulnberability - how many on your network?
mailing-list
x_refsource_BUGTRAQ
ADV-2007-0560
vdb-entry
x_refsource_VUPEN
solaris-telnet-authentication-bypass(32434)
vdb-entry
x_refsource_XF
VU#881872
third-party-advisory
x_refsource_CERT-VN
oval:org.mitre.oval:def:2202
vdb-entry
signature
x_refsource_OVAL
20070214 Solaris telnet vuln solutions digest and network risks
mailing-list
x_refsource_BUGTRAQ
24120
third-party-advisory
x_refsource_SECUNIA
20070211 "0day was the case that they gave me"
mailing-list
x_refsource_FULLDISC
1017625
vdb-entry
x_refsource_SECTRACK
http://isc.sans.org/diary.html?storyid=2220
x_refsource_MISC
102802
vendor-advisory
x_refsource_SUNALERT
31881
vdb-entry
x_refsource_OSVDB
22512
vdb-entry
x_refsource_BID
20070212 Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?
mailing-list
x_refsource_BUGTRAQ
20070214 RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network?
mailing-list
x_refsource_BUGTRAQ
20070213 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?
mailing-list
x_refsource_BUGTRAQ
TA07-059A
third-party-advisory
x_refsource_CERT
20070212 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now