Gnu Inetutils vulnerabilities
12 known vulnerabilities affecting gnu/inetutils.
Total CVEs
12
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH5MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-24061P1CRITICALCVSS 9.8KEVPoCRansomware≥ 1.9.3, ≤ 2.72026-01-21
CVE-2026-24061 [CRITICAL] CWE-88 CVE-2026-24061: telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for t
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
nvdosv
CVE-2011-4862P1CRITICALCVSS 10.0ExploitedPoCfixed in 1.92011-12-25
CVE-2011-4862 [CRITICAL] CWE-120 CVE-2011-4862: Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
nvdosv
CVE-2026-32746P2CRITICALCVSS 9.8PoC≤ 2.72026-03-13
CVE-2026-32746 [CRITICAL] CWE-120 CVE-2026-32746: telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Ch
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
nvdosv
CVE-2020-10188P2CRITICALCVSS 9.8≥ 0, < 2:1.9.4-122020-03-06
CVE-2020-10188 [CRITICAL] CVE-2020-10188: utility
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
osv
CVE-2014-3634P3HIGHCVSS 7.5≥ 0, < 2:1.9.2.39.3a460-12014-11-02
CVE-2014-3634 [HIGH] CVE-2014-3634: rsyslog before 7
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
osv
CVE-2026-28372P3HIGHCVSS 7.8≤ 2.72026-02-27
CVE-2026-28372 [HIGH] CWE-829 CVE-2026-28372: telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing sy
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth
nvdosv
CVE-2019-0053P3HIGHCVSS 7.8≥ 0, < 2:1.9.2-1ubuntu0.1~esm2≥ 0, < 2:1.9.4-1ubuntu0.1~esm3+1 more2025-09-28
CVE-2019-0053 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetut
osv
CVE-2023-40303P3HIGHCVSS 7.8≤ 2.42023-08-14
CVE-2023-40303 [HIGH] CWE-252 CVE-2023-40303: GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
nvdosv
CVE-2022-39028P3HIGHCVSS 7.5≤ 2.32022-08-30
CVE-2022-39028 [HIGH] CWE-476 CVE-2022-39028: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL p
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval,
nvdosv
CVE-2021-40491P4MEDIUMCVSS 6.5fixed in 2.22021-09-03
CVE-2021-40491 [MEDIUM] CVE-2021-40491: The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV respons
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
nvdosv
CVE-2026-32772P4MEDIUMCVSS 4.7≤ 2.72026-03-16
CVE-2026-32772 [MEDIUM] CWE-669 CVE-2026-32772: telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clie
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
nvdosv
CVE-2010-2529P4MEDIUMCVSS 5.0≥ 0, < 2:1.9-22010-07-28
CVE-2010-2529 [MEDIUM] CVE-2010-2529: Unspecified vulnerability in ping
Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafted echo response.
osv