Debian: netkit-telnet invalid free(3)

    Date02 Oct 2004
    CategoryDebian
    2596
    Posted ByLinuxSecurity Advisories
    Michal Zalewski discovered a bug in the netkit-telnet server (telnetd) whereby a remote attacker could cause the telnetd process to free an invalid pointer.
    
    --------------------------------------------------------------------------
    Debian Security Advisory DSA 556-1                     This email address is being protected from spambots. You need JavaScript enabled to view it. 
    http://www.debian.org/security/                             Matt Zimmerman
    October 2nd, 2004                        http://www.debian.org/security/faq
    --------------------------------------------------------------------------
    
    Package        : netkit-telnet
    Vulnerability  : invalid free(3)
    Problem-Type   : remote
    Debian-specific: yes
    CVE ID         : CAN-2004-0911
    Debian Bug     : 273694
    
    Michal Zalewski discovered a bug in the netkit-telnet server (telnetd)
    whereby a remote attacker could cause the telnetd process to free an
    invalid pointer.  This causes the telnet server process to crash,
    leading to a straightforward denial of service (inetd will disable the
    service if telnetd is crashed repeatedly), or possibly the execution
    of arbitrary code with the privileges of the telnetd process (by
    default, the 'telnetd' user).
    
    For the stable distribution (woody) this problem has been fixed in
    version 0.17-18woody1.
    
    For the unstable distribution (sid) this problem has been fixed in
    version 0.17-26.
    
    We recommend that you upgrade your netkit-telnetpackage.
    
    
    Upgrade Instructions
    --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 3.0 alias woody
    --------------------------------
    
      Source archives:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17-18woody1.dsc
          Size/MD5 checksum:      602 9b997bc6951c08c4f22c29dfe8fd6cfb
         http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17-18woody1.diff.gz
          Size/MD5 checksum:    22010 29a22dc590270539e60e040fe33678a3
         http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17.orig.tar.gz
          Size/MD5 checksum:   133749 d6beabaaf53fe6e382c42ce3faa05a36
    
      Alpha architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_alpha.deb
          Size/MD5 checksum:    84080 64e59060bcc7713c33051b129eb7a7b2
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_alpha.deb
          Size/MD5 checksum:    45712 dc1f4eba203e25e0e69fde84d0c68deb
    
      ARM architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_arm.deb
          Size/MD5 checksum:    69840 cee0940a812e1c14b3541bd408d8e772
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_arm.deb
          Size/MD5 checksum:    39534 78a51c224f171e029799183b8ba42357
    
      Intel IA-32 architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_i386.deb
          Size/MD5 checksum:    70668 8f16858a8702fa7840c60fa272f336b5
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_i386.deb
          Size/MD5 checksum:    37344 48eadf90962f7641c9b109e6ed0b31e4
    
      Intel IA-64 architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_ia64.deb
          Size/MD5 checksum:   102662 7ba021e10ae96097686b70c2b29c281d
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_ia64.deb
          Size/MD5 checksum:    52356 a87e16a648e472e06c0bcacdee2a3465
    
      HP Precision architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_hppa.deb
          Size/MD5 checksum:    69878 436ca10d3adf53cf95d0fb1532fe8ca4
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_hppa.deb
          Size/MD5 checksum:    43430 f782d2555aba39ac4a3fc375601cbe41
    
      Motorola 680x0 architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_m68k.deb
          Size/MD5 checksum:    67062 53604751760b712a28141bbfea772f02
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_m68k.deb
          Size/MD5 checksum:    37350 b8ba70a9e2b9c94edfbc2d5ad482f5f5
    
      Big endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_mips.deb
          Size/MD5 checksum:    80782 34f5870ce7c7e90a7337e4ace622c145
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_mips.deb
          Size/MD5 checksum:    42520 005a24828fe4c192cbcaaa1b9e4a4b09
    
      Little endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_mipsel.deb
          Size/MD5 checksum:    80670 b9cea5d2edda4f8c9453789c27aae058
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_mipsel.deb
          Size/MD5 checksum:    42490 cdb8fbe3737a45b2d215d36f8952c6ee
    
      PowerPC architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_powerpc.deb
          Size/MD5 checksum:    73142 0f784e76f7d00238a9e9b13b880682db
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_powerpc.deb
          Size/MD5 checksum:    40184 5e9eddd27a6424698068bc990a98e6da
    
      IBM S/390 architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_s390.deb
          Size/MD5 checksum:    73064 15178fb0215922e8084015c1745db52d
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_s390.deb
          Size/MD5 checksum:    41132 b8842ed3b2b92196b78872bfd7486dd6
    
      Sun Sparc architecture:
    
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_sparc.deb
          Size/MD5 checksum:    74078 367023264c0accb466316b5ef9479b54
         http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_sparc.deb
          Size/MD5 checksum:    45226 477922c39e0ed5ca85ff8209a93f6386
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    ---------------------------------------------------------------------------------
    For apt-get: deb  http://security.debian.org/ stable/updates main
    For dpkg-ftp:  ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and  http://packages.debian.org/
    
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"4","type":"x","order":"1","pct":57.14,"resources":[]},{"id":"88","title":"Should be more technical","votes":"2","type":"x","order":"2","pct":28.57,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"1","type":"x","order":"3","pct":14.29,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.