Because of incorrect bounds checking of data buffered for output to the remote client, an attacker can cause the telnetd process that is included in the JUNOS software to overflow a buffer and crash, or to execute arbitrary code as the root user. All that is required is the ability to connect to the telnetd server. A valid user account and password are not required to exploit this vulnerability. The complete text describing this vulnerability can be found at: ,br> ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.asc This vulnerability only affects the telnet service, and only if the service has been enabled in the Juniper router’s configuration. All other services, including ssh, are unaffected.
Replace the telnet daemon with a corrected version of the daemon. Use the procedure below to implement the patch for currently shipping versions of the JUNOS software. The fixed code will be included in all future versions of the JUNOS software.
A corrected version of the telnet daemon is available on the Juniper Networks FTP site: https://www.juniper.net/support/csc/swdist-export/updates/telnetd.20010724 ftp://ftp.juniper.net/private/junos/updates/telnetd.20010724 To download and install the corrected software, follow these steps (commands to be typed by the user are in bold ):