Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cfe888f1 by Salvatore Bonaccorso at 2020-04-07T22:36:12+02:00
Track inetutils under CVE-2020-10188

The respective functions in src:inetutils in utility.c correspond to
very similar code in netkit. Further investigation pending so far if
src:inetutils is due to as well affected by the CVE-2020-10188.

The same CVE could be used probably here due to same logic implemented
in the nextitem function.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3641,6 +3641,7 @@ CVE-2020-10190 (An issue was discovered in MunkiReport 
before 5.3.0. An authenti
 CVE-2020-10189 (Zoho ManageEngine Desktop Central before 10.0.474 allows 
remote code e ...)
        NOT-FOR-US: Zoho ManageEngine
 CVE-2020-10188 (utility.c in telnetd in netkit telnet through 0.17 allows 
remote attac ...)
+       - inetutils <unfixed> (bug #956084)
        - netkit-telnet 0.17-18woody2 (bug #953477)
        - netkit-telnet-ssl 0.17.17+0.1-2woody3 (bug #953478)
        NOTE: 
https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cfe888f14ac2cd32f1de7b38cd383c2cb63880fc

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cfe888f14ac2cd32f1de7b38cd383c2cb63880fc
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to