CyberSec.Space Logo
返回 CVE 浏览器

CVE-2007-0882

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0800%
EPSS Percentile32.33th
Published2007年2月12日
Last Modified2026年4月23日

Vulnerability Description

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Affected Platforms (CPE)

💻
Oracle

Solaris

= 10
💻
Oracle

Solaris

= 11
💻
Sun

Sunos

= 5.10
💻
Sun

Sunos

= 5.11

References & Advisories

相关漏洞威胁