CNCVE编号:CNCVE-20010554 CVE编号:CAN-2001-0554 安全级别:高 漏洞中文描述: 在各种操作系统中基于BSD的远程登录守护进程telnetd的缓冲区溢出,使得远程攻击者可以通过一组选项来执行任意的命令,这些选项包括AYT(Are You There),它不能被telrcv函数正确的处理。 漏洞英文描述: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. 漏洞参考: Reference: BUGTRAQ:20010718 multiple vendor telnet daemon vulnerability Reference: URL:http://www.securityfocus.com/archive/1/197804 Reference: CERT:CA-2000-21 Reference: URL:http://www.cert.org/advisories/CA-2001-21.html Reference: FREEBSD:FreeBS 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple其他 漏洞类型:输入有效性检查错误