This vulnerability has been assigned the identifier CAN-2001-0554
by the Common Vulnerabilities and Exposures (CVE) group:
Until a patch can be applied, you may wish to block access to the
Telnet service from outside your network perimeter. This will limit
your exposure to attacks. However, blocking port 23/tcp at a network
perimeter would still allow attackers within the perimeter of your
network to exploit the vulnerability. It is important to understand
your network's configuration and service requirements before deciding
what changes are appropriate.
Secure Computing Corporation
The telnetd vulnerability referenced is not applicable to
Sidewinder as a result of disciplined security software design
practices in combination with Secure Computing's patented Type
Enforcement(tm) technology. Sidewinder's telnetd services are greatly
restricted due to both known and theoretical vulnerabilities. This
least privilege design renders the attack described in the
CERT-2001-21 Advisory useless. In addition, Sidewinder's operating
system, SecureOS(tm), built on Secure's Type Enforcement technology,
has further defenses against this attack that would trigger multiple
security violations.
Specifically, the attack first attempts to start a shell
process. Sidewinder's embedded Type Enforcement security rules prevent
telnetd from replicating itself and accessing the system shell
programs. Even without this embedded, tamper proof rule in place,
other Type Enforcement rules also defend against this attack. As an
example, the new shell would need administrative privileges and those
privileges are not available to the telnetd services.
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4)
Monday through Friday; they are on call for emergencies during other
hours, on U.S. holidays, and on weekends.
We strongly urge you to encrypt sensitive information sent by
email. Our public PGP key is available from
If you prefer to use DES, please call the CERT hotline for more
information.
CERT publications and other security information are available from
our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
Copyright 2001 Carnegie Mellon University.