Skip to main content

Cisco IronPort Appliances telnetd Buffer Overflow Vulnerability

Last Update Date: 31 Jan 2012 11:46 Release Date: 31 Jan 2012 4710 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in some Cisco IronPort Appliances, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the "encrypt_keyid()" function (crypto/heimdal/appl/telnet/libtelnet/encrypt.c and contrib/telnet/libtelnet/encrypt.c), which can be exploited to cause a buffer overflow by sending specially crafted commands to the server.


Impact

  • Remote Code Execution

System / Technologies affected

  • Cisco IronPort Email Security Appliance (C-Series and X-Series) versions prior to 7.6.0.
  • Cisco IronPort Security Management Appliance (M-Series) versions prior to 7.8.0.

Solutions

  • Disable the telnet service or update to a fixed version when available

Vulnerability Identifier


Source


Related Link