Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Unix :: General :: ciacl128.txt

MIT Kerberos 5 telnetd Buffer Overflows


                       The U.S. Department of Energy
                     Computer Incident Advisory Center
                           ___  __ __    _     ___
                          /       |     /_\   /
                          \___  __|__  /   \  \___

                             INFORMATION BULLETIN

                    MIT Kerberos 5 telnetd Buffer Overflows

August 1, 2001 19:00 GMT                                          Number L-128
PROBLEM:       A buffer overflow exists in telnetd. 
PLATFORM:      MIT Kerberos 5, all releases to date. 
DAMAGE:        An unauthorized remote user can gain root access. 
SOLUTION:      Apply the appropriate patches and rebuild telnetd as prescribed 
               by MIT. 
VULNERABILITY  The risk is HIGH. The vulnerability has been discussed in open 
ASSESSMENT:    forums. 

[******  Start MIT Advisory ******]




Buffer overflows exist in the telnet daemon included with MIT krb5.
Exploits are believed to exist for various operating systems on at
least the i386 architecture.


If telnetd is running, a remote user may gain unauthorized root


* MIT Kerberos 5, all releases to date.


The recommended approach is to apply the appropriate patches and to
rebuild your telnetd.  Patches for the krb5-1.2.2 release may be found

The associated detached PGP signature is at:

These patches might apply successfully to older releases with some
amount of fuzz.

Please note that if you are using GNU make to build your krb5 sources,
the build system may attempt to rebuild the configure script from the
changed  This may cause trouble if you don't have
autoconf installed properly.  To prevent this, you should use the
touch command or some similar means to ensure that the file
modification time on the configure script is newer than that of the file.

If you are unable to patch your telnetd, you may should disable the
telnet service altogether.

This announcement and code patches related to it may be found on the
MIT Kerberos security advisory page at:

The main MIT Kerberos web page is at:


Thanks to TESO for the original alert / Bugtraq posting.

Thanks to Jeffrey Altman for assistance in developing these patches.


A buffer overflow bug was discovered in telnet daemons derived from
BSD source code.  Since the telnet daemon in MIT krb5 uses code
largely derived originally from BSD sources, it too is vulnerable.

By carefully constructing a series of telnet options to send to a
telnet server, a remote attacker may exercise a bug relating to lack
of bounds-checking, causing an overflow of a fixed-size buffer.  This
overflow may possibly force the execution of malicious code.

It is not known how difficult this vulnerability is to exploit, since
the buffer is not on the stack.  Some discussion seems to indicate
that exploits exist for this vulnerability that are believed to work
against various operating systems for i386-based machines.  It is not
known whether these existing exploits have been successfully ported to
other processors.

[******  End MIT Advisory ******]


CIAC wishes to acknowledge the contributions of MIT for the 
information contained in this bulletin.

CIAC, the Computer Incident Advisory Center, is the computer
security incident response team for the U.S. Department of Energy
(DOE) and the emergency backup response team for the National
Institutes of Health (NIH). CIAC is located at the Lawrence Livermore
National Laboratory in Livermore, California. CIAC is also a founding
member of FIRST, the Forum of Incident Response and Security Teams, a
global organization established to foster cooperation and coordination
among computer security teams worldwide.

CIAC services are available to DOE, DOE contractors, and the NIH. CIAC
can be contacted at:
    Voice:    +1 925-422-8193 (7x24)
    FAX:      +1 925-423-8002
    STU-III:  +1 925-423-2604

Previous CIAC notices, anti-virus software, and other information are
available from the CIAC Computer Security Archive.

   World Wide Web:
   Anonymous FTP:

PLEASE NOTE: Many users outside of the DOE, ESnet, and NIH computing
communities receive CIAC bulletins.  If you are not part of these
communities, please contact your agency's response team to report
incidents. Your agency's team will coordinate with CIAC. The Forum of
Incident Response and Security Teams (FIRST) is a world-wide
organization. A list of FIRST member organizations and their
constituencies can be obtained via WWW at

This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.

LAST 10 CIAC BULLETINS ISSUED (Previous bulletins available from CIAC)

L-118: Hewlett-Packard ftpd and ftp Vulnerability 
L-119: Hewlett-Packard mkacct Program Vulnerability
L-120: Cisco "Code Red" Worm Impact
L-121: SSH Secure Shell Remote Root Exploit Vulnerability
L-122: FreeBSD tcpdump Remote Buffer OVerflow Vulnerability
L-123: AIX libi18n Library Vulnerability
L-124: Remote Buffer Overflow in telnetd
L-125: SGI netprint Dynamic Shared Objects (DSO) Exploit
L-126: Microsoft Remote Procedure Call (RPC) Server Vulnerability
L-127: Sun BIND Vulnerabilities

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH