Cisco IronPort Appliances telnetd Buffer Overflow Vulnerability
Last Update Date:
31 Jan 2012 11:46
Release Date:
31 Jan 2012
5516
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in some Cisco IronPort Appliances, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the "encrypt_keyid()" function (crypto/heimdal/appl/telnet/libtelnet/encrypt.c and contrib/telnet/libtelnet/encrypt.c), which can be exploited to cause a buffer overflow by sending specially crafted commands to the server.
Impact
- Remote Code Execution
System / Technologies affected
- Cisco IronPort Email Security Appliance (C-Series and X-Series) versions prior to 7.6.0.
- Cisco IronPort Security Management Appliance (M-Series) versions prior to 7.8.0.
Solutions
- Disable the telnet service or update to a fixed version when available
Vulnerability Identifier
Source
Related Link
Share with