Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain root remotely >> SysV /bin/login buffer overflow (telnet)


Vulnerability Assessment Details

SysV /bin/login buffer overflow (telnet)

Vulnerability Assessment Summary
Attempts to overflow /bin/login

Detailed Explanation for this Vulnerability Assessment

The remote /bin/login seems to crash when it receives too many
environment variables.

A possible hacker may use this flaw to gain a root shell on this system.

See also : http://www.cert.org/advisories/CA-2001-34.html
Solution : Contact your vendor for a patch (or read the CERT advisory)
Network Security Threat Level: High

Networks Security ID: 3681, 7481

Vulnerability Assessment Copyright: This script is Copyright (C) 2001 Renaud Deraison

Cables, Connectors


IBM System X3250 M3 Server 8GB RAM Intel Xeon x3440 2.53ghz (NO HDD) picture

IBM System X3250 M3 Server 8GB RAM Intel Xeon x3440 2.53ghz (NO HDD)

$41.99



IBM System x3250 M4 Server Intel Xeon E31220/3.10Ghz RAM 16GB HDD 2TB picture

IBM System x3250 M4 Server Intel Xeon E31220/3.10Ghz RAM 16GB HDD 2TB

$79.00



IBM Power S822 8284-22A 12SFF Power8 3.89GHz 6Core 64GB RAM No HDD Server System picture

IBM Power S822 8284-22A 12SFF Power8 3.89GHz 6Core 64GB RAM No HDD Server System

$314.99



IBM EServer Xseries 220 Desktop Computer Intel Pentium 3 1GHz 512MB Ram No HDD picture

IBM EServer Xseries 220 Desktop Computer Intel Pentium 3 1GHz 512MB Ram No HDD

$224.99



IBM Server Rack Cabinet Machine Type 9308 Model 42P w/ Mounting Accessories picture

IBM Server Rack Cabinet Machine Type 9308 Model 42P w/ Mounting Accessories

$379.99



IBM x3650 M4 Server Intel Xeon E5-2640 (x2) 144GB RAM No HDDs (#4XN7N) picture

IBM x3650 M4 Server Intel Xeon E5-2640 (x2) 144GB RAM No HDDs (#4XN7N)

$119.99



IBM System X3650 M4 7915AC1 Server 2*Intel Xeon E5-2640 2.5GHz 32GB SEE NOTES  picture

IBM System X3650 M4 7915AC1 Server 2*Intel Xeon E5-2640 2.5GHz 32GB SEE NOTES

$59.00



IBM System x3550 M3 Dual Intel Xeon X5650 @2.67GHz 32GB RAM No HDD picture

IBM System x3550 M3 Dual Intel Xeon X5650 @2.67GHz 32GB RAM No HDD

$68.50



IBM System x3250 M4 Server Intel Xeon E31220/3.10Ghz RAM 16GB HDD 1TB picture

IBM System x3250 M4 Server Intel Xeon E31220/3.10Ghz RAM 16GB HDD 1TB

$79.00



IBM x3650 M4 2x Xeon E5-2670 2.6ghz 16-Core / 64GB / M5110e / 2x PSU picture

IBM x3650 M4 2x Xeon E5-2670 2.6ghz 16-Core / 64GB / M5110e / 2x PSU

$229.99



Discussions

No Discussions have been posted on this vulnerability.