Solaris ^D Character Remote Telnet Service DoS

medium Nessus Plugin ID 10272

Synopsis

The remote host is vulnerable to denial of service.

Description

It was possible to make the remote Sun crash by flooding it with ^D characters instead of entering our login.

This flaw allows an attacker to prevent your network from working properly.

Solution

Upgrade your telnet server and filter the incoming traffic to this port.

See Also

https://seclists.org/bugtraq/1997/Dec/71

Plugin Details

Severity: Medium

ID: 10272

File Name: sunkill.nasl

Version: 1.31

Type: remote

Published: 6/22/1999

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/o:sun:solaris

Required KB Items: Settings/ParanoidReport

Excluded KB Items: wingate/enabled

Vulnerability Publication Date: 1/1/1998

Reference Information

CVE: CVE-1999-0273