CVE-2006-0677
published 2006-02-14CVE-2006-0677: telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown…
PriorityP429high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.07%
86.2th percentile
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 0.7.2-1 (bookworm) | heimdal 0.7.2-1 (bookworm) |
| heimdal_project | heimdal | >= 0 < 0.7.2-1 | 0.7.2-1 |
| heimdal_project | heimdal | >= 0 < 0.7.2-1 | 0.7.2-1 |
| heimdal_project | heimdal | >= 0 < 0.7.2-1 | 0.7.2-1 |
| heimdal_project | heimdal | >= 0 < 0.7.2-1 | 0.7.2-1 |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rvx-m258-68cr: telnetd in Heimdal 0
ghsa_unreviewed·2022-05-01
CVE-2006-0677 [HIGH] GHSA-5rvx-m258-68cr: telnetd in Heimdal 0
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.
OSV
CVE-2006-0677: telnetd in Heimdal 0
osv·2006-02-14·CVSS 7.8
CVE-2006-0677 [HIGH] CVE-2006-0677: telnetd in Heimdal 0
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.
Ubuntu
heimdal vulnerability
vendor_ubuntu·2006-02-18
CVE-2006-0677 heimdal vulnerability
Title: heimdal vulnerability
Summary: heimdal vulnerability
A remote Denial of Service vulnerability was discovered in the heimdal
implementation of the telnet daemon. A remote attacker could force the
server to crash due to a NULL de-reference before the user logged in,
resulting in inetd turning telnetd off because it forked too fast.
Please note that the heimdal-servers package is not officially
supported in Ubuntu (it is in the 'universe' component of the
archive). However, this affects you if you use a customized version
built from the heimdal source package (which is supported).
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2006-0677: heimdal - telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unaut...
vendor_debian·2006·CVSS 7.8
CVE-2006-0677 [HIGH] CVE-2006-0677: heimdal - telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unaut...
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.
Scope: local
bookworm: resolved (fixed in 0.7.2-1)
bullseye: resolved (fixed in 0.7.2-1)
forky: resolved (fixed in 0.7.2-1)
sid: resolved (fixed in 0.7.2-1)
trixie: resolved (fixed in 0.7.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18894http://secunia.com/advisories/18961http://secunia.com/advisories/19005http://securityreason.com/securityalert/449http://www.debian.org/security/2006/dsa-977http://www.osvdb.org/23244http://www.securityfocus.com/archive/1/426043/100/0/threadedhttp://www.securityfocus.com/bid/16676http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.htmlhttp://www.ubuntu.com/usn/usn-253-1http://www.vupen.com/english/advisories/2006/0456http://www.vupen.com/english/advisories/2006/0628http://www.vupen.com/english/advisories/2006/0653https://exchange.xforce.ibmcloud.com/vulnerabilities/24763http://secunia.com/advisories/18894http://secunia.com/advisories/18961http://secunia.com/advisories/19005http://securityreason.com/securityalert/449http://www.debian.org/security/2006/dsa-977http://www.osvdb.org/23244http://www.securityfocus.com/archive/1/426043/100/0/threadedhttp://www.securityfocus.com/bid/16676http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.htmlhttp://www.ubuntu.com/usn/usn-253-1http://www.vupen.com/english/advisories/2006/0456http://www.vupen.com/english/advisories/2006/0628http://www.vupen.com/english/advisories/2006/0653https://exchange.xforce.ibmcloud.com/vulnerabilities/24763
2006-02-14
Published