CVE-2005-0469
published 2005-05-02CVE-2005-0469: Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
8.63%
94.5th percentile
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 0.6.3-11 (bookworm) | heimdal 0.6.3-11 (bookworm) |
| debian | heimdal | < heimdal 0.6.3-10 (bookworm) | heimdal 0.6.3-10 (bookworm) |
| debian | krb5 | < heimdal 0.6.3-10 (bookworm) | heimdal 0.6.3-10 (bookworm) |
| debian | netkit-telnet | < heimdal 0.6.3-10 (bookworm) | heimdal 0.6.3-10 (bookworm) |
| debian | netkit-telnet-ssl | < heimdal 0.6.3-10 (bookworm) | heimdal 0.6.3-10 (bookworm) |
| heimdal_project | heimdal | >= 0 < 0.6.3-11 | 0.6.3-11 |
| heimdal_project | heimdal | >= 0 < 0.6.3-10 | 0.6.3-10 |
| heimdal_project | heimdal | >= 0 < 0.6.3-11 | 0.6.3-11 |
| heimdal_project | heimdal | >= 0 < 0.6.3-10 | 0.6.3-10 |
| heimdal_project | heimdal | >= 0 < 0.6.3-11 | 0.6.3-11 |
| heimdal_project | heimdal | >= 0 < 0.6.3-10 | 0.6.3-10 |
| heimdal_project | heimdal | >= 0 < 0.6.3-11 | 0.6.3-11 |
| heimdal_project | heimdal | >= 0 < 0.6.3-10 | 0.6.3-10 |
| mit | krb5 | >= 0 < 1.3.6-2 | 1.3.6-2 |
| mit | krb5 | >= 0 < 1.3.6-2 | 1.3.6-2 |
| mit | krb5 | >= 0 < 1.3.6-2 | 1.3.6-2 |
| mit | krb5 | >= 0 < 1.3.6-2 | 1.3.6-2 |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
| telnetd | telnetd | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2005-12-06·CVSS 7.5
CVE-2005-0468 [HIGH] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Kerberos vulnerabilities
Gaël Delalleau discovered a buffer overflow in the env_opt_add()
function of the Kerberos 4 and 5 telnet clients. By sending specially
crafted replies, a malicious telnet server could exploit this to
execute arbitrary code with the privileges of the user running the
telnet client. (CVE-2005-0468)
Gaël Delalleau discovered a buffer overflow in the handling of the
LINEMODE suboptions in the telnet clients of Kerberos 4 and 5. By
sending a specially constructed reply containing a large number of SLC
(Set Local Character) commands, a remote attacker (i. e. a malicious
telnet server) could execute arbitrary commands with the privileges of
the user running the telnet client. (CVE-2005-0469)
Daniel Wachdorf discovered two remot
Ubuntu
telnet vulnerabilities
vendor_ubuntu·2005-03-29
CVE-2004-0911 telnet vulnerabilities
Title: telnet vulnerabilities
Summary: telnet vulnerabilities
A buffer overflow was discovered in the telnet client's handling of
the LINEMODE suboptions. By sending a specially constructed reply
containing a large number of SLC (Set Local Character) commands, a
remote attacker (i. e. a malicious telnet server) could execute
arbitrary commands with the privileges of the user running the telnet
client. (CAN-2005-0469)
Michal Zalewski discovered a Denial of Service vulnerability in the
telnet server (telnetd). A remote attacker could cause the telnetd
process to free an invalid pointer, which caused the server process to
crash, leading to a denial of service (inetd will disable the service
if telnetd crashed repeatedly), or possibly the execution of arbitrary
code with the privileges of t
Red Hat
security flaw
vendor_redhat·2005-03-28·CVSS 7.5
CVE-2005-0469 [HIGH] security flaw
security flaw
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-2040: heimdal - Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal...
vendor_debian·2005·CVSS 7.5
CVE-2005-2040 [HIGH] CVE-2005-2040: heimdal - Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal...
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.
Scope: local
bookworm: resolved (fixed in 0.6.3-11)
bullseye: resolved (fixed in 0.6.3-11)
forky: resolved (fixed in 0.6.3-11)
sid: resolved (fixed in 0.6.3-11)
trixie: resolved (fixed in 0.6.3-11)
Debian
CVE-2005-0469: heimdal - Buffer overflow in the slc_add_reply function in various BSD-based Telnet client...
vendor_debian·2005·CVSS 7.5
CVE-2005-0469 [HIGH] CVE-2005-0469: heimdal - Buffer overflow in the slc_add_reply function in various BSD-based Telnet client...
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
Scope: local
bookworm: resolved (fixed in 0.6.3-10)
bullseye: resolved (fixed in 0.6.3-10)
forky: resolved (fixed in 0.6.3-10)
sid: resolved (fixed in 0.6.3-10)
trixie: resolved (fixed in 0.6.3-10)
GHSA
GHSA-5hfw-w8jp-h4hj: Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execu
ghsa_unreviewed·2022-05-03
CVE-2005-0469 [HIGH] GHSA-5hfw-w8jp-h4hj: Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execu
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
GHSA
GHSA-r4rj-wjf2-m94v: Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2005-2040 [HIGH] GHSA-r4rj-wjf2-m94v: Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.
OSV
CVE-2005-2040: Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0
osv·2005-06-20·CVSS 7.5
CVE-2005-2040 [HIGH] CVE-2005-2040: Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.
OSV
CVE-2005-0469: Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execu
osv·2005-05-02·CVSS 7.5
CVE-2005-0469 [HIGH] CVE-2005-0469: Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execu
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
No detection rules found.
No public exploits indexed.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.ascftp://patches.sgi.com/support/free/security/advisories/20050405-01-Phttp://secunia.com/advisories/14745http://secunia.com/advisories/17899http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txthttp://www.debian.de/security/2005/dsa-731http://www.debian.org/security/2005/dsa-697http://www.debian.org/security/2005/dsa-699http://www.debian.org/security/2005/dsa-703http://www.gentoo.org/security/en/glsa/glsa-200503-36.xmlhttp://www.idefense.com/application/poi/display?id=220&type=vulnerabilitieshttp://www.kb.cert.org/vuls/id/291924http://www.mandriva.com/security/advisories?name=MDKSA-2005:061http://www.redhat.com/support/errata/RHSA-2005-327.htmlhttp://www.redhat.com/support/errata/RHSA-2005-330.htmlhttp://www.securityfocus.com/bid/12918http://www.ubuntulinux.org/usn/usn-224-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9708ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.ascftp://patches.sgi.com/support/free/security/advisories/20050405-01-Phttp://secunia.com/advisories/14745http://secunia.com/advisories/17899http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txthttp://www.debian.de/security/2005/dsa-731http://www.debian.org/security/2005/dsa-697http://www.debian.org/security/2005/dsa-699http://www.debian.org/security/2005/dsa-703http://www.gentoo.org/security/en/glsa/glsa-200503-36.xmlhttp://www.idefense.com/application/poi/display?id=220&type=vulnerabilitieshttp://www.kb.cert.org/vuls/id/291924http://www.mandriva.com/security/advisories?name=MDKSA-2005:061http://www.redhat.com/support/errata/RHSA-2005-327.htmlhttp://www.redhat.com/support/errata/RHSA-2005-330.htmlhttp://www.securityfocus.com/bid/12918http://www.ubuntulinux.org/usn/usn-224-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9708
2005-05-02
Published