[Git][security-tracker-team/security-tracker][master] Track inetutils under CVE-2020-10188

Salvatore Bonaccorso carnil at debian.org
Tue Apr 7 21:39:42 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cfe888f1 by Salvatore Bonaccorso at 2020-04-07T22:36:12+02:00
Track inetutils under CVE-2020-10188

The respective functions in src:inetutils in utility.c correspond to
very similar code in netkit. Further investigation pending so far if
src:inetutils is due to as well affected by the CVE-2020-10188.

The same CVE could be used probably here due to same logic implemented
in the nextitem function.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3641,6 +3641,7 @@ CVE-2020-10190 (An issue was discovered in MunkiReport before 5.3.0. An authenti
 CVE-2020-10189 (Zoho ManageEngine Desktop Central before 10.0.474 allows remote code e ...)
 	NOT-FOR-US: Zoho ManageEngine
 CVE-2020-10188 (utility.c in telnetd in netkit telnet through 0.17 allows remote attac ...)
+	- inetutils <unfixed> (bug #956084)
 	- netkit-telnet 0.17-18woody2 (bug #953477)
 	- netkit-telnet-ssl 0.17.17+0.1-2woody3 (bug #953478)
 	NOTE: https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cfe888f14ac2cd32f1de7b38cd383c2cb63880fc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cfe888f14ac2cd32f1de7b38cd383c2cb63880fc
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200407/e52f5277/attachment.html>


More information about the debian-security-tracker-commits mailing list