CVE-2000-0733 Information

Description

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

Reference

ftp://sgigate.sgi.com/security/20000801-02-P http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html http://www.securityfocus.com/bid/1572

Share on: