10

CVE-2007-0882

Exploit

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleSolaris Version10
OracleSolaris Version11
SunSunos Version5.10
SunSunos Version5.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.06% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

http://isc.sans.org/diary.html?storyid=2220
Third Party Advisory
Exploit
http://secunia.com/advisories/24120
Vendor Advisory
Broken Link
http://www.kb.cert.org/vuls/id/881872
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/459831/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/459843/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/459855/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/459980/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/460086/100/100/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/460103/100/100/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/22512
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1017625
Third Party Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-059A.html
Third Party Advisory
US Government Resource
Broken Link