Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpgv-x3r5-pm29

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

EPSS

Процентиль: 100%
0.90964
Критический

Дефекты

CWE-88
CWE-94

Связанные уязвимости

nvd
почти 19 лет назад

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

EPSS

Процентиль: 100%
0.90964
Критический

Дефекты

CWE-88
CWE-94