cbcvebase.
CVE-2020-10188
published 2020-03-06

CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos<= 4.20.15
aristaeos
aristaeos4.21.0 – 4.21.10m
aristaeos4.22 – 4.22.4m
aristaeos4.23 – 4.23.3m
debiandebian_linux
debiandebian_linux
debianinetutils< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
debiannetkit-telnet< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
debiannetkit-telnet-ssl< inetutils 2:1.9.4-12 (bookworm)inetutils 2:1.9.4-12 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.4-122:1.9.4-12
gnuinetutils>= 0 < 2:1.9.2-1ubuntu0.1~esm22:1.9.2-1ubuntu0.1~esm2
gnuinetutils>= 0 < 2:1.9.4-1ubuntu0.1~esm32:1.9.4-1ubuntu0.1~esm3
gnuinetutils>= 0 < 2:1.9.4-3ubuntu0.1+esm22:1.9.4-3ubuntu0.1+esm2
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL