Buffer overflow in telnet - CVE-2020-10188
Published: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary involving the netclear and nextitem functions within the utility.c in telnetd daemon from netkit telnet. A remote attacker can end specially crafted data to the telnetd daemon, trigger a boundary error and execute arbitrary code on the target system.
Affected software
FutureNet VXR/x64
FutureNet NXR-160/LW
FutureNet NXR-G200
FutureNet NXR-G180/L-CA
FutureNet NXR-G120
FutureNet NXR-G110
FutureNet NXR-G100
FutureNet NXR-G060
FutureNet NXR-G050
FutureNet NXR-130/C
FutureNet VXR/x86
FutureNet NXR-1200
FutureNet WXR-250
FutureNet NXR-120/C
FutureNet NXR-125/CX
FutureNet NXR-1300
FutureNet NXR-230/C
FutureNet NXR-155/C
FutureNet NXR-350/C
FutureNet NXR-530
FutureNet NXR-610X
FutureNet NXR-650
IPCOM VE1
IPCOM VA2
IPCOM VE2
IPCOM EX
IPCOM EX2
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Palo Alto PAN-OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Fedora
Arista Extensible Operating System (EOS)
telnet (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
telnet-help
telnet-debugsource
telnet
telnet-debuginfo
krb5-appl (Red Hat package)
inetutils (Ubuntu package)
inetutils-telnetd (Ubuntu package)
Oracle Communications Performance Intelligence Center (PIC) Software
How to mitigate CVE-2020-10188
FutureNet NXR-160/LW - update to 21.8.4
FutureNet NXR-G200 - update to 9.12.16
FutureNet NXR-G180/L-CA - update to 21.7.28C
FutureNet NXR-G120 - update to 21.15.2C
FutureNet NXR-G110 - update to 21.7.32
FutureNet NXR-G100 - update to 6.23.11
FutureNet NXR-G060 - update to 21.15.6
FutureNet NXR-G050 - update to 21.12.10
FutureNet VXR/x86 - update to 10.1.5
FutureNet NXR-1300 - update to 7.4.10
FutureNet NXR-230/C - update to 5.30.13
FutureNet NXR-350/C - update to 5.30.9C
FutureNet NXR-530 - update to 21.11.14
FutureNet NXR-610X - update to 21.14.11C
FutureNet NXR-650 - update to 21.16.2
IPCOM EX - update to E20L33 NF1101
telnet (Red Hat package) - addressed in versions 0.17-49.el6_10, 0.17-65.el7_6, 0.17-65.el7_7, 0.17-65.el7_8, 0.17-73.el8_0.1, 0.17-73.el8_1.1
IPCOM EX2 - update to V01L05 NF0501
Palo Alto PAN-OS - addressed in versions 8.1.20, 9.0.14, 9.1.9, 10.0.6
telnet-help - update to 0.17-76
telnet-debugsource - update to 0.17-76
telnet - update to 0.17-76
telnet-debuginfo - update to 0.17-76
telnet - addressed in versions 0.17-77.fc30, 0.17-78.fc31, 0.17-79.fc32
krb5-appl (Red Hat package) - update to 1.0.1-10.el6_10
inetutils (Ubuntu package) - addressed in versions 2:1.9.2-1ubuntu0.1~esm2, 2:1.9.4-1ubuntu0.1~esm3, 2:1.9.4-3ubuntu0.1+esm2, 2:1.9.4-11ubuntu0.2+esm1
inetutils-telnetd (Ubuntu package) - addressed in versions 2:1.9.4-3ubuntu0.1, 2:1.9.4-11ubuntu0.1
Arista Extensible Operating System (EOS) - addressed in versions 4.21.11M, 4.22.5M, 4.23.4M, 4.24.0.FX-KC, 4.24.1F
External References
- https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html
- https://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/
Related Security Bulletins
- Remote code execution in netkit telnet
- Red Hat Enterprise Linux 8 update for telnet
- Red Hat Enterprise Linux 6 update for telnet
- Red Hat Enterprise Linux 7 update for telnet
- Red Hat Enterprise Linux 8 update for telnet
- CentOS 6 update for telnet
- CentOS 6 update for krb5-appl
- Amazon Linux AMI update for telnet
- Multiple vulnerabilities in Oracle Communications Performance Intelligence Center Software
- Arch Linux update for inetutils
- Remote code execution in Telnet component in Palo Alto PAN-OS
- Red Hat Enterprise Linux 7.6 update for telnet
- Red Hat Enterprise Linux 7.7 update for telnet
- Multiple vulnerabilities in FUJITSU Network IPCOM
- Ubuntu update for inetutils
- Red Hat Enterprise Linux 6 update for krb5-appl
- openEuler 20.03 LTS update for telnet-0.17-76
- Multiple vulnerabilities in Century Systems FutureNet NXR series, VXR series and WXR series
- Fedora 31 update for telnet
- Fedora 32 update for telnet
- Fedora 30 update for telnet
- Arista EOS update for telnetd
- Ubuntu update for inetutils