Skip to main content

GNU inetutils telnetd Buffer Overflow Vulnerability

Last Update Date: 28 Dec 2011 15:28 Release Date: 28 Dec 2011 4784 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability has been identified in GNU inetutils, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the "encrypt_keyid()" function (libtelnet/encrypt.c), which can be exploited to cause a buffer overflow by sending specially crafted commands to the server.


Impact

  • Remote Code Execution

System / Technologies affected

  • GNU inetutils version 1.8.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Fixed in the GIT repository.

Vulnerability Identifier


Source


Related Link