COMMAND
ssl(-mz)telnet
SYSTEMS AFFECTED
Systems using ssl(-mz)telnet
PROBLEM
Christoph Martin found following. There is a security hole in the
versions 0.9.2 and 0.11.1 of SSL(-MZ)telnet. telnetd has a
debugging function in it which writes to /tmp/SSL.log. Some calls
to this function where not removed in the release version. If
someone would link /tmp/SSL.log to a system file and then telnet
into the machine the system file would be corrupted.
SOLUTION
All users of ssltelnet should update to the newest version, which
is 0.11.2. It is availlable from:
ftp://ftp.uni-mainz.de/pub/internet/security/ssl/SSL-MZapps/SSL-MZtelnet-0.11.2.tar.gz
or from it's mirrors. A new Debian Linux version was also
released and will appear soon on:
ftp://nonus.debian.org/pub/debian-non-US.