SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#291924

Multiple Telnet clients fail to properly handle the "LINEMODE" SLC suboption

Overview

Multiple Telnet clients contain a data length validation flaw which may allow a server to induce arbitrary code execution on the client host.

I. Description

The Telnet network protocol is described in RFC854 and RFC855 as a general, bi-directional communications facility. The Telnet protocol is commonly used for command line login sessions between Internet hosts.

Many Telnet client implementations may be vulnerable to a flaw which may allow arbitrary code to be executed on the connected client. The Telnet server may supply a specially crafted reply containing a larger number of RFC1184 LINEMODE "Set Local Character" (SLC) suboption commands, which are not checked for proper length before being stored into a fixed length buffer. Affected Telnet clients possibly include the BSD Telnet implementation and the MIT Kerberos distribution.

The Telnet LINEMODE mode is enabled by default in a majority of modern Telnet clients and servers, and is often negotiated automatically before user input is required. Therefore, an attacker may be able to launch a vulnerable client, for example, through commands embedded in web pages such as an IFRAME with a "telnet:" URL, and exploit this flaw requiring only minimal or no user interaction.

II. Impact

A remote server may be able to execute arbitrary code under the permissions of the user running the Telnet client on the local host.

III. Solution

Apply an update from your vendor

Patches, updates, and fixes are available from multiple vendors.
As a workaround, the client may explicitly disable the LINEMODE mode before connecting in order to prevent LINEMODE command processing. In addition, as a best practice clients should never connect to unknown servers.

Systems Affected

VendorStatusDate Updated
Apple Computer, Inc.Vulnerable1-Apr-2005
Cray Inc.Unknown29-Mar-2005
Debian LinuxVulnerable29-Mar-2005
EMC CorporationUnknown29-Mar-2005
EngardeUnknown29-Mar-2005
F5 Networks, Inc.Vulnerable2-May-2005
FreeBSD, Inc.Unknown29-Mar-2005
FujitsuUnknown29-Mar-2005
HitachiUnknown29-Mar-2005
HPUnknown29-Mar-2005
IBM CorporationUnknown29-Mar-2005
IBM eServerUnknown29-Mar-2005
IBM zSeriesUnknown29-Mar-2005
ImmunixUnknown29-Mar-2005
Ingrian Networks, Inc.Unknown29-Mar-2005
Juniper Networks, Inc.Unknown29-Mar-2005
Mandriva, Inc.Vulnerable1-Apr-2005
Mandriva, Inc.Unknown29-Mar-2005
Microsoft CorporationNot Vulnerable1-Apr-2005
MiT Kerberos Development TeamVulnerable29-Mar-2005
MontaVista Software, Inc.Unknown29-Mar-2005
NEC CorporationUnknown29-Mar-2005
NetBSDUnknown29-Mar-2005
NokiaUnknown29-Mar-2005
Novell, Inc.Unknown29-Mar-2005
OpenBSDUnknown29-Mar-2005
Openwall GNU/*/LinuxUnknown29-Mar-2005
Red Hat, Inc.Vulnerable22-Dec-2005
Sequent Computer Systems, Inc.Unknown29-Mar-2005
SGIUnknown29-Mar-2005
Sony CorporationUnknown29-Mar-2005
Sun Microsystems, Inc.Vulnerable29-Mar-2005
SUSE LinuxUnknown29-Mar-2005
The SCO Group (SCO Linux)Unknown29-Mar-2005
The SCO Group (SCO Unix)Unknown29-Mar-2005
TurboLinuxUnknown29-Mar-2005
UnisysUnknown29-Mar-2005
Wind River Systems, Inc.Unknown8-Aug-2005

References


http://www.idefense.com/application/poi/display?id=220&type=vulnerabilities
https://rhn.redhat.com/errata/RHSA-2005-327.html
http://secunia.com/advisories/14745/
http://web.mit.edu/kerberos/www/...s/MITKRB5-SA-2005-001-telnet.txt
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1
http://www.auscert.org.au/5134

Credit

Thanks to iDEFENSE Labs for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

Date Public03/28/2005
Date First Published03/29/2005 06:01:41 PM
Date Last Updated12/22/2005
CERT Advisory 
CVE NameCVE-2005-0469
US-CERT Technical Alerts 
Metric12.60
Document Revision29

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader