5
CVSSv2

CVE-2004-0911

Published: 03/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

telnetd for netkit 0.17 and previous versions, and possibly other versions, on Debian GNU/Linux allows remote malicious users to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.

Vulnerable Product Search on Vulmon Subscribe to Product

debian netkit

Vendor Advisories

A buffer overflow was discovered in the telnet client’s handling of the LINEMODE suboptions By sending a specially constructed reply containing a large number of SLC (Set Local Character) commands, a remote attacker (i e a malicious telnet server) could execute arbitrary commands with the privileges of the user running the telnet client (CAN- ...
Michal Zalewski discovered a bug in the netkit-telnet server (telnetd) whereby a remote attacker could cause the telnetd process to free an invalid pointer This causes the telnet server process to crash, leading to a straightforward denial of service (inetd will disable the service if telnetd is crashed repeatedly), or possibly the execution of ar ...