telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
Published Mar 6, 2020
9.8
CRITICALCVSS 3.1
EPSS 74.34%
Description
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Affected products
No data.
Configuration 1
- ≤ 0.17
Configuration 2
- 30
- 31
- 32
Configuration 3
- 8.0
- 9.0
Configuration 4
Configuration 5
- 10.4.0.2
Configuration 6
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3r12
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x48
- 12.3x50
- 12.3x50
- 12.3x50
- 12.3x50
- 12.3x50
- 12.3x50
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49-d30
- 15.1x49-d60
- 15.1x49-d140
- 15.1x49-d150
- 15.1x49-d160
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 16.1
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2
- 17.2x75
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.3
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 17.4
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.1
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75
- 18.2x75-d10
- 18.2x75-d30
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.3
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 18.4
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 20.1
- 20.1
- 20.1
No data.
Red Hat Enterprise Linux 6
krb5-appl-0:1.0.1-10.el6_10
Fixed · RHSA-2020:1349
Red Hat Enterprise Linux 6
telnet-1:0.17-49.el6_10
Fixed · RHSA-2020:1335
Red Hat Enterprise Linux 7
telnet-1:0.17-65.el7_8
Fixed · RHSA-2020:1334
Red Hat Enterprise Linux 7.6 Advanced Update Support
telnet-1:0.17-65.el7_6
Fixed · RHSA-2022:0011
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
telnet-1:0.17-65.el7_6
Fixed · RHSA-2022:0011
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
telnet-1:0.17-65.el7_6
Fixed · RHSA-2022:0011
Red Hat Enterprise Linux 7.7 Advanced Update Support
telnet-1:0.17-65.el7_7
Fixed · RHSA-2022:0158
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
telnet-1:0.17-65.el7_7
Fixed · RHSA-2022:0158
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
telnet-1:0.17-65.el7_7
Fixed · RHSA-2022:0158
Red Hat Enterprise Linux 8
telnet-1:0.17-73.el8_1.1
Fixed · RHSA-2020:1318
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
telnet-1:0.17-73.el8_0.1
Fixed · RHSA-2020:1342
Red Hat Enterprise Linux 5
telnet
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | krb5-appl-0:1.0.1-10.el6_10 | Fixed | RHSA-2020:1349 |
| Red Hat Enterprise Linux 6 | telnet-1:0.17-49.el6_10 | Fixed | RHSA-2020:1335 |
| Red Hat Enterprise Linux 7 | telnet-1:0.17-65.el7_8 | Fixed | RHSA-2020:1334 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | telnet-1:0.17-65.el7_6 | Fixed | RHSA-2022:0011 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | telnet-1:0.17-65.el7_6 | Fixed | RHSA-2022:0011 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | telnet-1:0.17-65.el7_6 | Fixed | RHSA-2022:0011 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | telnet-1:0.17-65.el7_7 | Fixed | RHSA-2022:0158 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | telnet-1:0.17-65.el7_7 | Fixed | RHSA-2022:0158 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | telnet-1:0.17-65.el7_7 | Fixed | RHSA-2022:0158 |
| Red Hat Enterprise Linux 8 | telnet-1:0.17-73.el8_1.1 | Fixed | RHSA-2020:1318 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | telnet-1:0.17-73.el8_0.1 | Fixed | RHSA-2020:1342 |
| Red Hat Enterprise Linux 5 | telnet | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterprise Linux host to be vulnerable, it must have telnet-server installed and the telnetd service enabled. Use of telnetd is not recommended, as it is an un-encrypted protocol with cleartext transmission of passwords; alternatives such as openssh are preferred.
Red Hat mitigation
When in enforcing mode, SELinux as configured in Red Hat Enterprise Linux provides some mitigation against an exploit for telnet-server, because it limits the kind of operations it can perform and programs that can be run from the telnet-server's context.
References (15)
- http://www.openwall.com/lists/oss-security/2026/01/20/8
- https://access.redhat.com/security/cve/CVE-2020-10188 Vendor Advisory
- https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1811673 Issue Tracking
- https://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00012.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00038.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-10188
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-10188
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.