Buffer overflow in telnet - CVE-2020-10188

 

Buffer overflow in telnet - CVE-2020-10188

Published: April 7, 2020


Vulnerability identifier: #VU26625
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10188
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary involving the netclear and nextitem functions within the utility.c in telnetd daemon from netkit telnet. A remote attacker can end specially crafted data to the telnetd daemon, trigger a boundary error and execute arbitrary code on the target system.


Affected software

telnet
FutureNet VXR/x64
FutureNet NXR-160/LW
FutureNet NXR-G200
FutureNet NXR-G180/L-CA
FutureNet NXR-G120
FutureNet NXR-G110
FutureNet NXR-G100
FutureNet NXR-G060
FutureNet NXR-G050
FutureNet NXR-130/C
FutureNet VXR/x86
FutureNet NXR-1200
FutureNet WXR-250
FutureNet NXR-120/C
FutureNet NXR-125/CX
FutureNet NXR-1300
FutureNet NXR-230/C
FutureNet NXR-155/C
FutureNet NXR-350/C
FutureNet NXR-530
FutureNet NXR-610X
FutureNet NXR-650
IPCOM VE1
IPCOM VA2
IPCOM VE2
IPCOM EX
IPCOM EX2
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Palo Alto PAN-OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Fedora
Arista Extensible Operating System (EOS)
telnet (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
telnet-help
telnet-debugsource
telnet
telnet-debuginfo
krb5-appl (Red Hat package)
inetutils (Ubuntu package)
inetutils-telnetd (Ubuntu package)
Oracle Communications Performance Intelligence Center (PIC) Software

How to mitigate CVE-2020-10188

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

FutureNet VXR/x64 - update to 21.7.32
FutureNet NXR-160/LW - update to 21.8.4
FutureNet NXR-G200 - update to 9.12.16
FutureNet NXR-G180/L-CA - update to 21.7.28C
FutureNet NXR-G120 - update to 21.15.2C
FutureNet NXR-G110 - update to 21.7.32
FutureNet NXR-G100 - update to 6.23.11
FutureNet NXR-G060 - update to 21.15.6
FutureNet NXR-G050 - update to 21.12.10
FutureNet VXR/x86 - update to 10.1.5
FutureNet NXR-1300 - update to 7.4.10
FutureNet NXR-230/C - update to 5.30.13
FutureNet NXR-350/C - update to 5.30.9C
FutureNet NXR-530 - update to 21.11.14
FutureNet NXR-610X - update to 21.14.11C
FutureNet NXR-650 - update to 21.16.2
IPCOM EX - update to E20L33 NF1101
telnet (Red Hat package) - addressed in versions 0.17-49.el6_10, 0.17-65.el7_6, 0.17-65.el7_7, 0.17-65.el7_8, 0.17-73.el8_0.1, 0.17-73.el8_1.1
IPCOM EX2 - update to V01L05 NF0501
Palo Alto PAN-OS - addressed in versions 8.1.20, 9.0.14, 9.1.9, 10.0.6
telnet-help - update to 0.17-76
telnet-debugsource - update to 0.17-76
telnet - update to 0.17-76
telnet-debuginfo - update to 0.17-76
telnet - addressed in versions 0.17-77.fc30, 0.17-78.fc31, 0.17-79.fc32
krb5-appl (Red Hat package) - update to 1.0.1-10.el6_10
inetutils (Ubuntu package) - addressed in versions 2:1.9.2-1ubuntu0.1~esm2, 2:1.9.4-1ubuntu0.1~esm3, 2:1.9.4-3ubuntu0.1+esm2, 2:1.9.4-11ubuntu0.2+esm1
inetutils-telnetd (Ubuntu package) - addressed in versions 2:1.9.4-3ubuntu0.1, 2:1.9.4-11ubuntu0.1
Arista Extensible Operating System (EOS) - addressed in versions 4.21.11M, 4.22.5M, 4.23.4M, 4.24.0.FX-KC, 4.24.1F

External References

Related Security Bulletins