Title: Multiple Vendor talkd(8) Vulnerability
Severity: CRITICAL
Description:
The program talk is used to provide a two-way screen-oriented conversation between users. The talkd daemon is used to notify a user that another users wishes to establish a chat session. As part of this process, talkd must perform a name lookup of the initiating host. Due to a buffer overflow condition in talkd related to the name lookup facility, an unauthorized user may be able to pass bogus hostname information to talkd and gain root access.
Affected Products:
- BSDI BSD/OS 1.1.0
- BSDI BSD/OS 2.0.0
- BSDI BSD/OS 2.0.1
- BSDI BSD/OS 2.1.0
- Debian Linux 0.93.0
- Debian Linux 1.1.0
- FreeBSD FreeBSD 1.1.5 .1
- FreeBSD FreeBSD 2.0.0
- FreeBSD FreeBSD 2.0.5
- FreeBSD FreeBSD 2.1.0
- FreeBSD FreeBSD 2.1.5
- FreeBSD FreeBSD 2.1.6
- HP HP-UX (VVOS) 10.24.0
- HP HP-UX 10.0.0
- HP HP-UX 10.1.0 0
- HP HP-UX 10.10.0
- HP HP-UX 10.16.0
- HP HP-UX 10.20.0
- HP HP-UX 10.30.0
- HP HP-UX 10.34.0
- HP HP-UX 10.8.0
- HP HP-UX 10.9.0
- IBM AIX 3.2.0
- IBM AIX 4.1.0
- IBM AIX 4.2.0
- NEC EWS-UX/V (Rel4.2)
- NEC EWS-UX/V (Rel4.2MP)
- NEC UP-UX/V (Rel4.2MP)
- NEC UX/4800 (64)
- RedHat Linux 2.0.0
- RedHat Linux 2.1.0
- RedHat Linux 3.0.3
- SGI IRIX 4.0.0
- SGI IRIX 4.0.1
- SGI IRIX 4.0.2
- SGI IRIX 4.0.3
- SGI IRIX 4.0.4
- SGI IRIX 4.0.4 B
- SGI IRIX 4.0.4 T
- SGI IRIX 4.0.5
- SGI IRIX 4.0.5 (IOP)
- SGI IRIX 4.0.5 A
- SGI IRIX 4.0.5 D
- SGI IRIX 4.0.5 E
- SGI IRIX 4.0.5 F
- SGI IRIX 4.0.5 G
- SGI IRIX 4.0.5 H
- SGI IRIX 4.0.5 IPR
- SGI IRIX 5.0.0
- SGI IRIX 5.0.1
- SGI IRIX 5.1.0
- SGI IRIX 5.1.1
- SGI IRIX 5.2.0
- SGI IRIX 5.3.0
- SGI IRIX 5.3.0 XFS
- SGI IRIX 6.0.0
- SGI IRIX 6.0.1
- SGI IRIX 6.0.1 XFS
- SGI IRIX 6.1.0
- SGI IRIX 6.2.0
- SGI IRIX 6.3.0
- SGI IRIX 6.4.0
References:
- Hewlett Packard: HP Electronic Support Center for Europe
- Hewlett Packard: HP Electronic Support Center for US, Canada, Asia-Pacific, & Latin-America
- IBM: IBM Support Databases
- Sun Microsystems: Sun Patch Access Page
- Sun Microsystems: Sun Patches List
- Sun Microsystems: Sunsolve Online(tm)
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.