xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

telnetd-ssl AYT存在远程缓冲溢出漏洞


发布时间:2001-08-15
更新时间:2001-08-15
严重程度:
威胁程度:普通用户访问权限
错误类型:输入验证错误
利用方式:服务器模式

受影响系统
netkit-telnet-ssl_0.16.3-1
详细描述
Debian GNU/Linux 的'stable'(potato)版本中的netkit-telnet-ssl_0.16.3-1
守护程序存在对输入处理不当的缓冲溢出,这个漏洞是由<scut@nb.in-berlin.de>
发现的,详细描述可以参看以前的帖子,因为debian使用'telnetd'用户运行了
in.telnetd,因此远程的溢出不能直接得到ROOT SHELL。

测试代码
尚无

解决方案
下载升级程序:
Debian GNU/Linux 2.2 alias potato
- ---------------------------------


  Potato was released for alpha, arm, i386, m68k, powerpc and sparc.


  Source archives:
    http://security.debian.org/dists/stable/updates/main/source/netkit-telnet-ssl_0.16.3-1.1.diff.gz
      MD5 checksum: 953d3006b9491a441799f73633a72f05
    http://security.debian.org/dists/stable/updates/main/source/netkit-telnet-ssl_0.16.3-1.1.dsc
      MD5 checksum: aed9ded4b4d69dd852dfd5320a8a9cf5
    http://security.debian.org/dists/stable/updates/main/source/netkit-telnet-ssl_0.16.3.orig.tar.gz
      MD5 checksum: 999a416e11e9a9750b0ec2428eeabe1d


  Alpha architecture:
    http://security.debian.org/dists/stable/updates/main/binary-alpha/ssltelnet_0.16.3-1.1_alpha.deb
      MD5 checksum: 92680b907a65008e04cc0cf16ce1d87f
    http://security.debian.org/dists/stable/updates/main/binary-alpha/telnet-ssl_0.16.3-1.1_alpha.deb
      MD5 checksum: 4d4f6e8ee1e06eacb416de4733f45170
    http://security.debian.org/dists/stable/updates/main/binary-alpha/telnetd-ssl_0.16.3-1.1_alpha.deb
      MD5 checksum: dec52e65bb6304fd353e2af33adedb7c


  ARM architecture:
    http://security.debian.org/dists/stable/updates/main/binary-arm/ssltelnet_0.16.3-1.1_arm.deb
      MD5 checksum: 668f8343d7e6ed824a55d8510723cc2a
    http://security.debian.org/dists/stable/updates/main/binary-arm/telnet-ssl_0.16.3-1.1_arm.deb
      MD5 checksum: c3bacf45513033a66bfefcf370e295c9
    http://security.debian.org/dists/stable/updates/main/binary-arm/telnetd-ssl_0.16.3-1.1_arm.deb
      MD5 checksum: 3241dbd7380b97edec177305694891ae


  Intel IA-32 architecture:
    http://security.debian.org/dists/stable/updates/main/binary-i386/ssltelnet_0.16.3-1.1_i386.deb
      MD5 checksum: aec70bdc25994a1a885fac130a426ddc
    http://security.debian.org/dists/stable/updates/main/binary-i386/telnet-ssl_0.16.3-1.1_i386.deb
      MD5 checksum: 4b97d30b1417a9e2ebb8d941c9486451
    http://security.debian.org/dists/stable/updates/main/binary-i386/telnetd-ssl_0.16.3-1.1_i386.deb
      MD5 checksum: a6d456dc0a9789436dd4f92ace9dadf6


  Motorola 680x0 architecture:
    http://security.debian.org/dists/stable/updates/main/binary-m68k/ssltelnet_0.16.3-1.1_m68k.deb
      MD5 checksum: a38f77d83afc1daeb9b23a91cdd90478
    http://security.debian.org/dists/stable/updates/main/binary-m68k/telnet-ssl_0.16.3-1.1_m68k.deb
      MD5 checksum: 0cb485fb260ac74b411b8b82bd299d04
    http://security.debian.org/dists/stable/updates/main/binary-m68k/telnetd-ssl_0.16.3-1.1_m68k.deb
      MD5 checksum: 3c6cfd4542145edac7a9c4b55a59a896


  PowerPC architecture:
    http://security.debian.org/dists/stable/updates/main/binary-powerpc/ssltelnet_0.16.3-1.1_powerpc.deb
      MD5 checksum: 983ec249db831da8f01e730f5265207e
    http://security.debian.org/dists/stable/updates/main/binary-powerpc/telnet-ssl_0.16.3-1.1_powerpc.deb
      MD5 checksum: f069f9a731337b7bcc60db23ca2707ee
    http://security.debian.org/dists/stable/updates/main/binary-powerpc/telnetd-ssl_0.16.3-1.1_powerpc.deb
      MD5 checksum: 3627da7c28bb071a157f2cab29bd4ad9


  Sun Sparc architecture:
    http://security.debian.org/dists/stable/updates/main/binary-sparc/ssltelnet_0.16.3-1.1_sparc.deb
      MD5 checksum: 7c108a2fd7d4a86513baa3849076882a
    http://security.debian.org/dists/stable/updates/main/binary-sparc/telnet-ssl_0.16.3-1.1_sparc.deb
      MD5 checksum: 8951b3d32c086ba5fe81a3f62578dd89
    http://security.debian.org/dists/stable/updates/main/binary-sparc/telnetd-ssl_0.16.3-1.1_sparc.deb
      MD5 checksum: 5ca8897ae2bb3afeb3a0c1b0f34677bc

相关信息