View Single Post
  #1  
Old 31st Mar 05, 11:30 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,981
NewsBot will become famous soon enough
UNIX Authors Rush to Patch Telnet Flaw
Several high-profile distributors of the BSD version of the Telnet protocol have rolled out patches for a critical bug that could cause system-hijack attacks. The bug, which was reported by iDefense Inc., is a remotely exploitable buffer overflow that could allow the execution of arbitrary code with user privileges.

A successful attacker would have to convince the user to launch a Telnet session with a malicious server. A malicious Web page could be designed that could launch the Telnet client on the user's system by clicking a link, or, using the IFRAME tag, by loading the page. Telnet is a protocol that supports virtual terminal sessions across IP networks including the Internet. The Telnet client program provides the interface for the terminal session to the user.

News source: Neowin
Full story: View Here
Reply With Quote