Debians sikkerhedsbulletin
DSA-070-1 netkit-telnet -- fjernangreb
- Rapporteret den:
- 10. aug 2001
- Berørte pakker:
- netkit-telnet
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 3064.
I Mitres CVE-ordbog: CVE-2001-0554. - Yderligere oplysninger:
-
netkit-telnet-daemon'en i
telnetd
-pakken med version 0.16-4potato1, som distribueres med den "stabile" (2.2 potato) distribution af Debian GNU/Linux, er sårbar overfor et angreb mod dens uddatahåndtering.Den oprindelige fejl blev fundet af <scut@nb.in-berlin.de>, og annonceret på bugtraq den 18. juli 2001. På det tidspunkt troede man ikke at netkit-telnet versioner eter 0.14 var sårbare.
Den 10. august 2001 postede zen-parse et bulletin baseret på det samme problem gældende for alle netkit-telnet version under 0.17.
Flere detaljer findes på http://online.securityfocus.com/archive/1/203000. Da Debian anvender `telnetd'-brugeren til at køre
in.telnetd
, er dette ikke et fjernangreb mod root på Debian-systemer; men brugeren `telnetd' kan kompromitteres.Vi anbefaler kraftigt at du opdaterer din
telnetd
-pakke til versionen listet herunder. - Rettet i:
-
Debian GNU/Linux 2.2 (potato)
- Kildekode:
- http://security.debian.org/dists/stable/updates/main/source/netkit-telnet_0.16-4potato.2.diff.gz
- http://security.debian.org/dists/stable/updates/main/source/netkit-telnet_0.16.orig.tar.gz
- http://security.debian.org/dists/stable/updates/main/source/netkit-telnet_0.16-4potato.2.dsc
- http://security.debian.org/dists/stable/updates/main/source/netkit-telnet_0.16.orig.tar.gz
- Alpha:
- http://security.debian.org/dists/stable/updates/main/binary-alpha/telnet_0.16-4potato.2_alpha.deb
- http://security.debian.org/dists/stable/updates/main/binary-alpha/telnetd_0.16-4potato.2_alpha.deb
- http://security.debian.org/dists/stable/updates/main/binary-alpha/telnetd_0.16-4potato.2_alpha.deb
- ARM:
- http://security.debian.org/dists/stable/updates/main/binary-arm/telnet_0.16-4potato.2_arm.deb
- http://security.debian.org/dists/stable/updates/main/binary-arm/telnetd_0.16-4potato.2_arm.deb
- http://security.debian.org/dists/stable/updates/main/binary-arm/telnetd_0.16-4potato.2_arm.deb
- Intel IA-32:
- http://security.debian.org/dists/stable/updates/main/binary-i386/telnet_0.16-4potato.2_i386.deb
- http://security.debian.org/dists/stable/updates/main/binary-i386/telnetd_0.16-4potato.2_i386.deb
- http://security.debian.org/dists/stable/updates/main/binary-i386/telnetd_0.16-4potato.2_i386.deb
- Motorola 680x0 architecture:
- http://security.debian.org/dists/stable/updates/main/binary-m68k/telnet_0.16-4potato.2_m68k.deb
- http://security.debian.org/dists/stable/updates/main/binary-m68k/telnetd_0.16-4potato.2_m68k.deb
- http://security.debian.org/dists/stable/updates/main/binary-m68k/telnetd_0.16-4potato.2_m68k.deb
- PowerPC:
- http://security.debian.org/dists/stable/updates/main/binary-powerpc/telnet_0.16-4potato.2_powerpc.deb
- http://security.debian.org/dists/stable/updates/main/binary-powerpc/telnetd_0.16-4potato.2_powerpc.deb
- http://security.debian.org/dists/stable/updates/main/binary-powerpc/telnetd_0.16-4potato.2_powerpc.deb
- Sun Sparc:
- http://security.debian.org/dists/stable/updates/main/binary-sparc/telnet_0.16-4potato.2_sparc.deb
- http://security.debian.org/dists/stable/updates/main/binary-sparc/telnetd_0.16-4potato.2_sparc.deb
- http://security.debian.org/dists/stable/updates/main/binary-sparc/telnetd_0.16-4potato.2_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.