Sun Offers Fixes for Solaris Telnet Worm

The United States Computer Emergency Readiness Team (US-CERT) has issued an alert warning of a worm that exploits a vulnerability in the Sun Solaris telnet daemon. The flaw could be exploited to gain unauthorized access to a host using the service. Sun Microsystems has made available a patch and a workaround for the flaw, as well as an inoculation script to disable the telnet daemon and repair changes the worm has made.

Internet Storm Center (published far earlier than most other major
organizations): http://isc.sans.org/diary.html?storyid=2316

I would have to add to this; that simply using telnet is vulnerability and the patch (that has been available for years) is called SSH.

Stop using telnet! It floors me how often I go to configure a hardware firewall to find that telnet is left open or is the only remote shell available. Stop it!