Family: Debian Local Security Checks --> Category: infos
[DSA070] DSA-070-1 netkit-telnet Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
The netkit-telnet daemon contained in the telnetd package version
0.16-4potato1, which is shipped with
the "stable" (2.2, potato) distribution of Debian GNU/Linux, is vulnerable to an
exploitable overflow in its output handling.
The original bug was found by , and announced to
bugtraq on Jul 18 2001. At that time, netkit-telnet versions after 0.14 were
not believed to be vulnerable.
On Aug 10 2001, zen-parse posted an advisory based on the same problem, for
all netkit-telnet versions below 0.17.
More details can be found on http://online.securityfocus.com/archive/1/203000.
As Debian uses the `telnetd' user to run in.telnetd, this is not a remote
root compromise on Debian systems
however, the user `telnetd' can be compromised.
We strongly advise you update your telnetd package to the versions
Solution : http://www.debian.org/security/2001/dsa-070
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.