Debian Security Advisory

DSA-070-1 netkit-telnet -- remote exploit

Date Reported:
10 Aug 2001
Affected Packages:
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 3064.
In Mitre's CVE dictionary: CVE-2001-0554.
More information:
The netkit-telnet daemon contained in the telnetd package version 0.16-4potato1, which is shipped with the "stable" (2.2, potato) distribution of Debian GNU/Linux, is vulnerable to an exploitable overflow in its output handling.

The original bug was found by <>, and announced to bugtraq on Jul 18 2001. At that time, netkit-telnet versions after 0.14 were not believed to be vulnerable.

On Aug 10 2001, zen-parse posted an advisory based on the same problem, for all netkit-telnet versions below 0.17.

More details can be found on As Debian uses the `telnetd' user to run in.telnetd, this is not a remote root compromise on Debian systems; however, the user `telnetd' can be compromised.

We strongly advise you update your telnetd package to the versions listed below.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Intel IA-32:
Motorola 680x0 architecture:
Sun Sparc:

MD5 checksums of the listed files are available in the original advisory.