Solaris Telnet Login Authentication Bypass

Notification Type: IBM Internet Security Systems Protection Alert
Notification Date: Feb 13, 2007
Notification Version: 1.2
   
Name: Solaris Telnet Login Authentication Bypass
Public disclosure/
In the wild date:
Feb 11, 2007 (vuln and PoC)
CVE: CVE-2007-0882
Description:

X-Force has been tracking a worm that exploits this issue.  If the telnet daemon is enabled, Sun Solaris could allow a remote attacker to bypass authentication and gain root-level privileges.

 

ISS Coverage

Product Content Version
Network Sensor 7.0
Proventia A
Proventia IPS (G/GX) prior to Firmware Version 1.2
Server Sensor 7.0
24.56
Proventia IPS (G/GX) Firmware Version 1.2 or
later
Proventia Multifunction Appliance
Proventia Server (Linux)
1.95
Proventia Server (Windows) 1.0.914.1960
Proventia Desktop x.x.x.1960
RealSecure Desktop 7.0 (AM SP 6.73 or 7.73) EQB
BlackICE PC Protection 3.6 CQB
Enterprise Scanner 1.17
Internet Scanner 7.2.38
Propagation Techniques ISS Protection Available
remote exploit Telnet_User_Environment_Bypass Feb 15, 2007
Detection Techniques ISS Detection Available
network assessment solaris-telnet-authentication-bypass Feb 15, 2007
anomaly detection solaris-telnet-scanning-possible-worm Feb 28, 2007

Detailed Description

Business Impact: Gain Access 
CVSS: Base Score: 8
  Access Vector: Remote
Access Complexity: High
Authentication: Not Required 
Confidentiality Impact: Complete 
Integrity Impact: Complete 
Availability Impact: Complete 
Impact Bias: Normal 
Adjusted Temporal Score: 7.2
  Exploitability: High
Remediation Level: Temporary-Fix
Report Confidence: Confirmed 
Affected Products:

Solaris 10

Technical Description:

A flaw in the telnet daemon allows a remote attacker to gain the privileges of a known user account (like root or any other admin account).

A remote attacker could send a specially-crafted telnet login request to bypass authentication and gain unauthorized access to the system.

Remediation instructions: Refer to Sun Alert ID: 102802 for Interim Security Relief (ISR) or suggested workaround information. See References.

References

XFDB:  http://xforce.iss.net/xforce/xfdb/32434 
Sun: http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1

Revision History

1.0 Initial alert.
1.1 Updated signature and check date.
1.2 Updated CVSS score and added worm information

* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

About IBM Security Systems

IBM Security Systems include an extensive portfolio of hardware, software solutions, professional and managed services offerings covering the spectrum of IT and business security risks: people and identity, data and information, application and process, network, server and endpoint and physical infrastructure, empowering clients to innovate and operate their businesses on the most secure infrastructure platforms. Through world-class solutions that address risk across the enterprise, IBM helps organizations build a strong security posture that helps reduce costs, improve service, and manage risk. IBM X-Force(R) Research and Development is one of the most renowned commercial security research and development groups in the world. For more information on how to address today's biggest risks, please visit us at ibm.com/security.