utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
21 Nov 2024, 04:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html - Third Party Advisory | |
References | () https://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216Â - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/05/msg00012.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/08/msg00038.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/Â - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/Â - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/Â - | |
References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx - Third Party Advisory | |
References | () https://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48Â - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory |
Information
Published : 2020-03-06 15:15
Updated : 2024-11-21 04:54
NVD link : CVE-2020-10188
Mitre link : CVE-2020-10188
CVE.ORG link : CVE-2020-10188
JSON object : View
Products Affected
oracle
- communications_performance_intelligence_center
debian
- debian_linux
fedoraproject
- fedora
arista
- eos
netkit_telnet_project
- netkit_telnet
juniper
- junos
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')