vendor:
Windows
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Windows
Affected Version From: Windows 98, ME, NT 4.0, and 2000
Affected Version To: Windows 98, ME, NT 4.0, and 2000
Patch Exists: Yes
Related CWE: CVE-2001-0206
CPE: o:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
Hilgraeve HyperTerminal Buffer Overflow Vulnerability
A buffer overflow condition exists when a user attempts to access a telnet address over 153 characters long. Depending on the data entered, a denial of service attack or arbitrary code could be launched by a malicious third party. A specially malformed telnet address could be launched on a remote system if it were embedded in a HTML page or email message.
Mitigation:
Users should ensure that they are running the latest version of HyperTerminal and that they are not using it as the default telnet client.