Executive brief
A vulnerability in the Telnet service of older SunOS operating systems allows a user who already has a basic account on the system to gain full administrative (root) control. This could allow an unauthorized individual to access any file, modify system settings, or disrupt operations. This issue primarily affects legacy systems running SunOS version 4.1.1 or older.
Technical details
A vulnerability exists in the in.telnetd daemon on SunOS 4.1.1 and earlier. The flaw allows a local attacker with authenticated access to the system to exploit the Telnet service to escalate their privileges to root. While the specific technical root cause (such as a buffer overflow or environment variable manipulation) is not detailed in the summary, the impact is a complete compromise of the host's integrity, confidentiality, and availability. This is a legacy vulnerability originally disclosed in 1991. Patches were historically made available by the vendor.
Affected products
- Sun Microsystems SunOS 4.1.1 and earlier
Timeline
- 1991-03-27: advisory: NVD published date
- 1991-03-27: disclosed: Original CERT advisory date