Executive brief
A vulnerability in the Telnet service of Solaris 2.5.1 allows an attacker to crash or disrupt the service. By sending specific control characters (Ctrl-D) over the network, a remote user can cause a denial of service. This impacts the ability of administrators and users to remotely access and manage the affected system.
Technical details
The Telnet daemon in Sun Solaris 2.5.1 (SunOS 5.5.1) is susceptible to a denial of service attack. An unauthenticated remote attacker can trigger the vulnerability by sending a sequence of '^D' (EOF) characters during a telnet session. This causes the service to malfunction or terminate, preventing further remote access via the telnet protocol. The issue is rooted in improper handling of control characters within the telnet stream.
Affected products
- Sun Microsystems Solaris 2.5.1
- Sun Microsystems SunOS 5.5.1
Timeline
- 1998-01-01: disclosed: Initial publication date in NVD