telnet-0.17-49.AXS4

エラータID: AXSA:2020-4689:02

Release date: 
Monday, April 6, 2020 - 16:45
Subject: 
telnet-0.17-49.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Telnet is a popular protocol for logging in to remote systems over the Internet. The telnet-server packages include a telnet service that supports remote logins into the host machine. The telnet service is disabled by default.

Security Fix(es):

* telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. telnet-0.17-49.AXS4.src.rpm
    MD5: 329e1bf962f8052e7167c81d314ea4d8
    SHA-256: e271b5ef00de662a292fc283ada5a8e19032d44442680195eee3ada30ba0e0c8
    Size: 279.84 kB

Asianux Server 4 for x86
  1. telnet-0.17-49.AXS4.i686.rpm
    MD5: 595fed35a14b2dbc424af23e12ab1628
    SHA-256: f9d34b34bb9c17b800c0372506285567f7420371413c76e8eca89a68be36c487
    Size: 56.43 kB
  2. telnet-server-0.17-49.AXS4.i686.rpm
    MD5: 541b211e3ae49fee097077e821f140f6
    SHA-256: daa85fdfb0da2859c142539107e01725789289908c104a913fb5e25073f46a79
    Size: 36.27 kB

Asianux Server 4 for x86_64
  1. telnet-0.17-49.AXS4.x86_64.rpm
    MD5: 4f71c09e2a2ffa0dc9351b5f31a71d2f
    SHA-256: d8348df9e0bba060be524fb9bfb0619c048b3ccb9259e9216b5af387b42c102b
    Size: 57.19 kB
  2. telnet-server-0.17-49.AXS4.x86_64.rpm
    MD5: bbac90ec3cf7631f6ce2588f6fedd6ea
    SHA-256: b616f35abf3fe7b44df9e97989009dc137f3ae7ca8440df2925c9f8d71ce4524
    Size: 36.39 kB