SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#220816

MIT Kerberos 5 telnet daemon allows login as arbitrary user

Overview

A vulnerability exists in the version of the telnet daemon included with the MIT Kerberos 5 distribution that may allow a remote, unauthorized attacker to log on to the system with elevated privileges.

I. Description

A vulnerability exists version of the telnet daemon included with the MIT Kerberos 5 distribution that may allow a remote, unauthenticated user to login as any valid user, including root. According to MIT krb5 Security Advisory MITKRB5-SA-2007-001:

    The MIT krb5 telnet daemon fails to adequately check the provided username. A malformed username beginning with "-e" can be interpreted as a command-line flag by the login.krb5 program, which is executed by telnetd. This causes login.krb5 to execute part of the BSD rlogin protocol, where an arbitrary username may be injected, allowing login as that user without a password or any further authentication.

Note that this issue affects all releases of MIT krb5 up to and including krb5-1.6.

II. Impact

A remote attacker could log on to a vulnerable system via telnet with elevated privileges. This impact is limited to authenticated users if the telnet daemon is configured to only allow authenticated login.

III. Solution

Apply Patch

A patch can be obtained from MIT krb5 Security Advisory MITKRB5-SA-2007-001. MIT also states that this will be addressed in the upcoming krb5-1.6.1 release.

Systems Affected

VendorStatusDate Updated
3com, Inc.Unknown21-Mar-2007
AlcatelUnknown21-Mar-2007
Apple Computer, Inc.Unknown21-Mar-2007
AttachmateWRQ, Inc.Not Vulnerable2-Apr-2007
AT&TUnknown21-Mar-2007
Avaya, Inc.Unknown21-Mar-2007
Avici Systems, Inc.Unknown21-Mar-2007
Borderware TechnologiesUnknown21-Mar-2007
Charlotte's Web NetworksUnknown21-Mar-2007
Check Point Software TechnologiesUnknown21-Mar-2007
Chiaro Networks, Inc.Unknown21-Mar-2007
Cisco Systems, Inc.Unknown21-Mar-2007
ClavisterUnknown21-Mar-2007
Computer AssociatesUnknown21-Mar-2007
Conectiva Inc.Unknown21-Mar-2007
Cray Inc.Unknown21-Mar-2007
CyberSafe, Inc.Not Vulnerable22-Mar-2007
D-Link Systems, Inc.Unknown21-Mar-2007
Data Connection, Ltd.Unknown21-Mar-2007
Debian GNU/LinuxVulnerable4-Apr-2007
EMC, Inc. (formerly Data General Corporation)Unknown21-Mar-2007
Engarde Secure LinuxUnknown21-Mar-2007
EricssonUnknown21-Mar-2007
eSoft, Inc.Unknown21-Mar-2007
Extreme NetworksUnknown21-Mar-2007
F5 Networks, Inc.Unknown21-Mar-2007
Fedora ProjectVulnerable12-Apr-2007
Force10 Networks, Inc.Not Vulnerable28-Mar-2007
Fortinet, Inc.Unknown21-Mar-2007
Foundry Networks, Inc.Unknown21-Mar-2007
FreeBSD, Inc.Unknown21-Mar-2007
FujitsuUnknown21-Mar-2007
Gentoo LinuxVulnerable4-Apr-2007
Global Technology AssociatesUnknown21-Mar-2007
Heimdal Kerberos ProjectNot Vulnerable30-Mar-2007
Hewlett-Packard CompanyNot Vulnerable16-May-2007
HitachiNot Vulnerable2-Apr-2007
HyperchipUnknown21-Mar-2007
IBM CorporationUnknown21-Mar-2007
IBM Corporation (zseries)Unknown21-Mar-2007
IBM eServerUnknown21-Mar-2007
Immunix Communications, Inc.Unknown21-Mar-2007
Ingrian Networks, Inc.Unknown21-Mar-2007
Intel CorporationUnknown21-Mar-2007
Internet Security Systems, Inc.Unknown21-Mar-2007
IntotoNot Vulnerable28-Mar-2007
IP FilterUnknown21-Mar-2007
Juniper Networks, Inc.Not Vulnerable28-Mar-2007
KTH Kerberos TeamUnknown21-Mar-2007
Linksys (A division of Cisco Systems)Unknown21-Mar-2007
Lucent TechnologiesUnknown21-Mar-2007
Luminous NetworksUnknown21-Mar-2007
Mandriva, Inc.Vulnerable5-Apr-2007
Microsoft CorporationNot Vulnerable28-Mar-2007
MIT Kerberos Development TeamVulnerable3-Apr-2007
MontaVista Software, Inc.Unknown21-Mar-2007
Multinet (owned Process Software Corporation)Unknown21-Mar-2007
Multitech, Inc.Unknown21-Mar-2007
NEC CorporationNot Vulnerable6-Apr-2007
NetBSDUnknown21-Mar-2007
netfilterUnknown21-Mar-2007
Network Appliance, Inc.Unknown21-Mar-2007
NextHop Technologies, Inc.Unknown21-Mar-2007
NokiaUnknown21-Mar-2007
Nortel Networks, Inc.Unknown21-Mar-2007
Novell, Inc.Unknown21-Mar-2007
OpenBSDUnknown21-Mar-2007
Openwall GNU/*/LinuxNot Vulnerable28-Mar-2007
QNX, Software Systems, Inc.Unknown21-Mar-2007
Red Hat, Inc.Vulnerable4-Apr-2007
Redback Networks, Inc.Unknown21-Mar-2007
Riverstone Networks, Inc.Unknown21-Mar-2007
rPathVulnerable5-Apr-2007
Secure Computing Network Security DivisionUnknown21-Mar-2007
Secureworx, Inc.Unknown21-Mar-2007
Silicon Graphics, Inc.Unknown21-Mar-2007
Slackware Linux Inc.Unknown21-Mar-2007
Sony CorporationUnknown21-Mar-2007
StonesoftUnknown21-Mar-2007
Sun Microsystems, Inc.Vulnerable23-Apr-2007
SUSE LinuxVulnerable5-Apr-2007
Symantec, Inc.Not Vulnerable5-Apr-2007
The SCO GroupUnknown21-Mar-2007
Trustix Secure LinuxVulnerable6-Apr-2007
TurbolinuxUnknown21-Mar-2007
UbuntuVulnerable4-Apr-2007
UnisysUnknown21-Mar-2007
Watchguard Technologies, Inc.Unknown21-Mar-2007
Wind River Systems, Inc.Unknown21-Mar-2007
ZyXELUnknown21-Mar-2007

References


http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-001-telnetd.txt
http://secunia.com/advisories/24757/
http://secunia.com/advisories/24735/
http://secunia.com/advisories/24750/
http://secunia.com/advisories/24740/
http://secunia.com/advisories/24755/
http://securitytracker.com/alerts/2007/Apr/1017848.html

Credit

This issue was reported in MIT krb5 Security Advisory MITKRB5-SA-2007-001.

This document was written by Chris Taschner.

Other Information

Date Public04/03/2007
Date First Published04/03/2007 05:25:12 PM
Date Last Updated05/16/2007
CERT Advisory 
CVE NameCVE-2007-0956
US-CERT Technical Alerts 
Metric17.85
Document Revision38

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader