{"id":"CVE-2007-0882","aliases":[],"url":"https://o3.security/vulnerability/CVE-2007-0882","summary":"Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client \"-f\" sequences as valid requests for the login…","details":"Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client \"-f\" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.","published":"2007-02-12T20:00:00.000Z","modified":"2024-08-07T12:34:21.133Z","cvss":null,"epss":{"score":0.97848,"percentile":0.99903,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":6,"affectedPackages":[],"fix":null,"references":[{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/459843/100/0/threaded"},{"type":"WEB","url":"http://www.vupen.com/english/advisories/2007/0560"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32434"},{"type":"ADVISORY","url":"http://www.kb.cert.org/vuls/id/881872"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2202"},{"type":"WEB","url":"http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html"},{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/460086/100/100/threaded"},{"type":"ADVISORY","url":"http://secunia.com/advisories/24120"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2007/Feb/0217.html"},{"type":"WEB","url":"http://www.securitytracker.com/id?1017625"},{"type":"WEB","url":"http://isc.sans.org/diary.html?storyid=2220"},{"type":"ADVISORY","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1"},{"type":"WEB","url":"http://osvdb.org/31881"},{"type":"WEB","url":"http://www.securityfocus.com/bid/22512"},{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/459831/100/0/threaded"},{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/460103/100/100/threaded"},{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/459980/100/0/threaded"},{"type":"ADVISORY","url":"http://www.us-cert.gov/cas/techalerts/TA07-059A.html"},{"type":"REPORT","url":"http://www.securityfocus.com/archive/1/459855/100/0/threaded"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-07T12:34:21.133Z"}}