Vulnerability Description
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sgi | Irix | 5.2 |
References
- ftp://sgigate.sgi.com/security/20000801-02-P
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1572ExploitVendor Advisory
- ftp://sgigate.sgi.com/security/20000801-02-P
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1572ExploitVendor Advisory
FAQ
What is CVE-2000-0733?
CVE-2000-0733 is a vulnerability with a CVSS score of 10.0 (HIGH). Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-T...
How severe is CVE-2000-0733?
CVE-2000-0733 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0733?
Check the references section above for vendor advisories and patch information. Affected products include: Sgi Irix.