Do your applications use this vulnerable package?
Test your applications
Overview
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-10188
- CWE
- CWE-120
- Snyk ID
- SNYK-DEBIAN9-INETUTILS-564742
- Disclosed
- 06 Mar, 2020
- Published
- 07 Mar, 2020