| Sun Solaris telnet authentication bypass (SolarisTelnetAuthenticationBypass) |
|---|
| Vuln ID: | 32434 | |
|---|---|---|
| Risk Level: | High |
SolarisTelnetAuthenticationBypass |
| Platforms: | Sun Solaris: 10 SPARC, Sun Solaris: 10 x86 | |
| Description: | Sun Solaris could allow a remote attacker to bypass authentication, caused by an error in the telnet daemon (in.telnetd). A remote attacker could send a specially-crafted telnet login request to bypass authentication and gain unauthorized access to the system. Note: Remote root login must be enabled to gain root privileges. |
|
| Remedy: | Refer to Sun Alert ID: 102802 for upgrade or suggested workaround information. See References. |
|
| False Positives: | It is possible that some telnet servers may send some combination of telnet options that cause this check to generate a false positive even though the server is, in fact, not vulnerable. | |
| False Negatives: | It is possible that some telnet servers may send some combination of telnet options that cause this check to generate a false negative even though the server is, in fact, vulnerable. | |
| Required Permission: | ||
| Additional Information: | ||
| References: | US-CERT Vulnerability Note VU#881872 Full-Disclosure Mailing List, Mon Feb 12 2007 - 16:05:05 CST Sun Microsystems, Inc. Web site Full-Disclosure Mailing List, Sat Feb 10 2007 - 22:59:56 CST FrSIRT/ADV-2007-0560 Sun Alert ID: 102802 US-CERT Technical Cyber Security Alert TA07-059A Security Sun Alert Feed, 28 Feb 2007 ISS X-Force CVE CVE-2007-0882 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |