Sun Information for VU#745371
Multiple vendor telnet daemons vulnerable to buffer overflow via crafted protocol options
- Vendor Information Help Date Notified: 24 Jul 2001
- Statement Date:
- Date Updated: 16 Apr 2002
A buffer overflow has been discovered in in.telnetd which allows a local or a remote attacker to kill the in.telnetd daemon on the affected SunOS system. Sun does not believe that this issue can be exploited on SunOS systems to gain elevated privileges. As there was a buffer overflow, Sun has generated patches for this issue. The patches are described in the following SunAlert:
and are available from:
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.