CVE-2020-10188

high
Published 2020-04-06 Β· Modified 2020-04-06
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2020:1318: telnet security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code Red Hat statement This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterprise Linux host to be vulnerable, it must have telnet-server installed and the telnetd service enabled. Use of telnetd is not recommended, as it is an…

Description

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code

Red Hat statement

This vulnerability exists in the `telnet-server` package, not in the `telnet` client-side package. For a Red Hat Enterprise Linux host to be vulnerable, it must have telnet-server installed and the telnetd service enabled. Use of telnetd is not recommended, as it is an un-encrypted protocol with cleartext transmission of passwords; alternatives such as openssh are preferred.

CVSS v3: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 6telnet-1:0.17-49.el6_10RHSA-2020:13352020-04-06T00:00:00Z
Red Hat Enterprise Linux 6krb5-appl-0:1.0.1-10.el6_10RHSA-2020:13492020-04-07T00:00:00Z
Red Hat Enterprise Linux 7telnet-1:0.17-65.el7_8RHSA-2020:13342020-04-06T00:00:00Z
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)telnet-1:0.17-65.el7_6RHSA-2022:00112022-01-04T00:00:00Z
Red Hat Enterprise Linux 7.6 Telco Extended Update Supporttelnet-1:0.17-65.el7_6RHSA-2022:00112022-01-04T00:00:00Z
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutionstelnet-1:0.17-65.el7_6RHSA-2022:00112022-01-04T00:00:00Z
Red Hat Enterprise Linux 7.7 Advanced Update Supporttelnet-1:0.17-65.el7_7RHSA-2022:01582022-01-18T00:00:00Z
Red Hat Enterprise Linux 7.7 Telco Extended Update Supporttelnet-1:0.17-65.el7_7RHSA-2022:01582022-01-18T00:00:00Z
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutionstelnet-1:0.17-65.el7_7RHSA-2022:01582022-01-18T00:00:00Z
Red Hat Enterprise Linux 8telnet-1:0.17-73.el8_1.1RHSA-2020:13182020-04-06T00:00:00Z
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionstelnet-1:0.17-73.el8_0.1RHSA-2020:13422020-04-07T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 5telnetOut of support scope

Apply commands

bash fix
Apply RHSA-2020:1335 for Red Hat Enterprise Linux 6
yum update -y telnet
# or:
dnf upgrade -y telnet

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 2.0-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2:1.9.4-12
sid Fixed 2:1.9.4-12
forky Fixed 2:1.9.4-12
bullseye Fixed 2:1.9.4-12
bookworm Fixed 2:1.9.4-12
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.