CVE-2000-0733: Critical severity sgi irix vulnerability
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPTENVIRON request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0733?
CVE-2000-0733 is considered a critical vulnerability as it allows remote attackers to execute arbitrary commands on vulnerable systems.
How do I fix CVE-2000-0733?
To fix CVE-2000-0733, update your IRIX telnetd to a version that does not contain the format string vulnerability.
Which versions of SGI IRIX are affected by CVE-2000-0733?
CVE-2000-0733 affects SGI IRIX versions from 5.2 to 6.5.8 inclusive.
What kind of attack can be performed using CVE-2000-0733?
An attacker can exploit CVE-2000-0733 to execute arbitrary commands remotely via specially crafted Telnet requests.
Is there a workaround for CVE-2000-0733 if I cannot immediately patch?
As a temporary workaround for CVE-2000-0733, consider disabling the Telnet service or restricting access to trusted hosts only.