Buffer overflow in the handlepacket function in mactelnet.c in the client in MAC-Telnet 0.4.3 and earlier allows remote TELNET servers to execute arbitrary code via a long string in an MTCPTYPE_PASSSALT control packet.
{ "urgency": "not yet assigned" }