CVE-2001-0554
published 2001-08-14CVE-2001-0554: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options…
PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
37.90%
98.4th percentile
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catos_telnet | — | — |
| debian | debian_linux | — | — |
| debian | netkit | <= 0.17 | — |
| debian | netkit-telnet | < netkit-telnet 0.17-26 (bullseye) | netkit-telnet 0.17-26 (bullseye) |
| debian | netkit-telnet-ssl | < netkit-telnet 0.17-26 (bullseye) | netkit-telnet 0.17-26 (bullseye) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit triggers the vulnerability via the AYT (Are You There) telnet option combined with other telnet protocol options sent to port 23; detect anomalous sequences of IAC option negotiations (especially IAC WILL/DO with options 0x03, 0x18, 0x1f, 0x20, 0x21, 0x22, 0x23, 0x27, 0x05) in a single session. ↗
- →Monitor for a new listening port 7465 opened by in.telnetd process after exploitation; this is the backdoor bind shell spawned by the shellcode. ↗
- →The exploit sets environment variables USER and TERM to 'zen-parse' during the NEW-ENVIRONMENT telnet sub-negotiation; alert on telnet NEW-ENVIRONMENT (option 39) submissions containing these values. ↗
- →A worm is known to be actively exploiting this vulnerability in the wild; prioritize detection on internet-facing telnetd instances. ↗
- →The overflow occurs in the telrcv() function during processing of heap-based telnet option responses; heap corruption artifacts (e.g., invalid free, corrupted malloc chunks) in telnetd crash logs are indicative of exploitation attempts. ↗
- →On Cisco CatOS, exploitation causes the Telnet daemon to crash and results in a switch reload; unexpected switch reloads on Catalyst devices with telnet enabled should be investigated for this CVE. ↗
- ·The proof-of-concept exploit is tuned for RedHat 7.0 localhost and requires adjustment of --size and --name options for other targets; offsets are host-specific. ↗
- ·Exploitability depends on the hostname length returned by the AYT command (multiples of 3 letters affect the heap layout); brute-forcing may be required. ↗
- ·Many heap-using processes affect the required --size offset, making reliable exploitation environment-dependent. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2004-0911: netkit-telnet - telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/...
vendor_debian·2004·CVSS 10.0
CVE-2004-0911 [CRITICAL] CVE-2004-0911: netkit-telnet - telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/...
telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.
Scope: local
bullseye: resolved (fixed in 0.17-26)
Cisco
Cisco VPN 3000 Concentrator Multiple Vulnerabilities
vendor_cisco·2002-09-03
CVE-2001-0554 CWE-119 Cisco VPN 3000 Concentrator Multiple Vulnerabilities
Cisco VPN 3000 Concentrator Multiple Vulnerabilities
The Cisco VPN 3000 series concentrators are a family of purpose-built,
remote access Virtual Private Network (VPN) platforms for data encryption and
authentication.
This advisory documents multiple vulnerabilities for the Cisco VPN 3000
series concentrators and Cisco VPN 3002 Hardware Client. These vulnerabilities
are documented as Cisco bug ID's CSCdt56514, CSCdu15622, CSCdu35577,
CSCdu82823, CSCdv66718, CSCdv88230, CSCdw22408, CSCdw50657, CSCdx07754,
CSCdx24622, CSCdx24632, CSCdx39981, CSCdx54675 and CSCdy38035. Upgrading to the
latest version of code for the Cisco VPN 3000 series concentrators and Cisco
VPN 3002 Hardware Client, version 3.5.5 or 3.6.1, would protect against all of
these documented vulnerabilities.
This advisory wil
Cisco
Cisco CatOS Telnet Buffer Vulnerability
vendor_cisco·2002-01-29
CVE-2001-0554 CWE-119 Cisco CatOS Telnet Buffer Vulnerability
Cisco CatOS Telnet Buffer Vulnerability
Some Cisco Catalyst switches, running certain CatOS based software
releases, have a vulnerability wherein a buffer overflow in the Telnet option
handling can cause the Telnet daemon to crash and result in a switch reload.
This vulnerability can be exploited to initiate a denial of service
(DoS) attack. This vulnerability is documented as Cisco bug ID CSCdw19195.
There are workarounds available to mitigate the vulnerability.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020129-catos-telrcv.
Red Hat
security flaw
vendor_redhat·2001-07-18·CVSS 10.0
CVE-2001-0554 [CRITICAL] security flaw
security flaw
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Cisco
Cisco CatOS Telnet Buffer Vulnerability
vendor_cisco
CVE-2001-0554 Cisco CatOS Telnet Buffer Vulnerability
CVE-2001-0554: Cisco CatOS Telnet Buffer Vulnerability
Some Cisco Catalyst switches, running certain CatOS based software releases, have a vulnerability wherein a buffer overflow in the Telnet option handling can cause the Telnet daemon to crash and result in a switch reload. This vulnerability can be exploited to initiate a denial of service (DoS) attack. This vulnerability is documented as Cisco bug ID CSCdw19195. There are
CWE: CWE-119, CWE-119
Bug IDs: CSCdw19195, CSCdw19195
GHSA
GHSA-cxg3-hwc8-9mx4: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of opt
ghsa_unreviewed·2022-05-03
CVE-2001-0554 [HIGH] CWE-120 GHSA-cxg3-hwc8-9mx4: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of opt
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
GHSA
GHSA-qwfx-f35q-fm98: telnetd for netkit 0
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2004-0911 [CRITICAL] GHSA-qwfx-f35q-fm98: telnetd for netkit 0
telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.
OSV
CVE-2004-0911: telnetd for netkit 0
osv·2004-11-03·CVSS 10.0
CVE-2004-0911 [CRITICAL] CVE-2004-0911: telnetd for netkit 0
telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.
VulnCheck
mit kerberos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
vulncheck·2001·CVSS 10.0
CVE-2001-0554 [CRITICAL] mit kerberos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
mit kerberos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Affected: mit kerberos
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.exploit-db.com/exploits/21018
No detection rules found.
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.ascftp://patches.sgi.com/support/free/security/advisories/20010801-01-Pftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txthttp://archives.neohapsis.com/archives/hp/2001-q4/0014.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000413http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtmlhttp://online.securityfocus.com/advisories/3476http://online.securityfocus.com/archive/1/199496http://online.securityfocus.com/archive/1/199541http://online.securityfocus.com/archive/1/203000http://www.calderasystems.com/support/security/advisories/CSSA-2001-030.0.txthttp://www.cert.org/advisories/CA-2001-21.htmlhttp://www.ciac.org/ciac/bulletins/l-131.shtmlhttp://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtmlhttp://www.debian.org/security/2001/dsa-070http://www.debian.org/security/2001/dsa-075http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-068.php3http://www.novell.com/linux/security/advisories/2001_029_nkitb_txt.htmlhttp://www.osvdb.org/809http://www.redhat.com/support/errata/RHSA-2001-099.htmlhttp://www.redhat.com/support/errata/RHSA-2001-100.htmlhttp://www.securityfocus.com/archive/1/197804http://www.securityfocus.com/bid/3064https://exchange.xforce.ibmcloud.com/vulnerabilities/6875ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.ascftp://patches.sgi.com/support/free/security/advisories/20010801-01-Pftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txthttp://archives.neohapsis.com/archives/hp/2001-q4/0014.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000413http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtmlhttp://online.securityfocus.com/advisories/3476http://online.securityfocus.com/archive/1/199496http://online.securityfocus.com/archive/1/199541http://online.securityfocus.com/archive/1/203000http://www.calderasystems.com/support/security/advisories/CSSA-2001-030.0.txthttp://www.cert.org/advisories/CA-2001-21.htmlhttp://www.ciac.org/ciac/bulletins/l-131.shtmlhttp://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtmlhttp://www.debian.org/security/2001/dsa-070http://www.debian.org/security/2001/dsa-075http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-068.php3http://www.novell.com/linux/security/advisories/2001_029_nkitb_txt.htmlhttp://www.osvdb.org/809http://www.redhat.com/support/errata/RHSA-2001-099.htmlhttp://www.redhat.com/support/errata/RHSA-2001-100.htmlhttp://www.securityfocus.com/archive/1/197804http://www.securityfocus.com/bid/3064https://exchange.xforce.ibmcloud.com/vulnerabilities/6875
2001-08-14
Published
Exploited in the wild