SunOS : telnetd patch!

Patch-ID# 110668-03
Keywords: security gettext telnetd TTYPROMPT remote buffer overflow
Synopsis: SunOS 5.8: /usr/sbin/in.telnetd patch
Date: Jan/18/2002

Solaris Release: 8

SunOS Release: 5.8

Unbundled Product: Unbundled Release: Xref: This patch available for x86 as patch 110669

Topic: SunOS 5.8: /usr/sbin/in.telnetd patch

Relevant Architectures: sparc

BugId's fixed with this patch: 4366956 4375449 4483514 4516876 4523990 4527873

Changes incorporated in this version: 4483514 4523990 4527873

Patches accumulated and obsoleted by this patch: Patches which conflict with this patch: Patches required with this patch: Obsoleted by: Files included with this patch: /usr/sbin/in.telnetd

Problem Description:

4483514 in.telnetd vulnerable to buffer overflow ??
4523990 in.telnetd needs some cleanup
4527873 telnetd issues garbage before login prompt if BANNER in use
(from 110668-02)
4516876 in.telnetd should not accept TTYPROMPT from remote
(from 110668-01)
4366956 NLSPATH gettext introduces problems when used printf format specifier
4375449 dtmail crashes when calling catgets with NULL default message

Special Install Instructions:
         NOTE:    To get the complete fix for 4366956 (NLSPATH gettext
                  introduces problems when used printf format specifier),
                  we recommend installing the following patches:
                  110670-01 (or newer)   /usr/sbin/static/rcp patch
                  108991-06 (or newer)   /usr/lib/libc.a
                  109091-04 (or newer)   /usr/sbin/ufsrestore

