Back

CRITICAL

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code

Published Mar 6, 2020

Description

utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

Affected products

Remediation

Red Hat statement

This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterprise Linux host to be vulnerable, it must have telnet-server installed and the telnetd service enabled. Use of telnetd is not recommended, as it is an un-encrypted protocol with cleartext transmission of passwords; alternatives such as openssh are preferred.

Red Hat mitigation

When in enforcing mode, SELinux as configured in Red Hat Enterprise Linux provides some mitigation against an exploit for telnet-server, because it limits the kind of operations it can perform and programs that can be run from the telnet-server's context.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 6, 2020
Updated Jan 21, 2026
Reserved Mar 6, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 28, 2020