Release date: 2011-12-26
Updated on: 2011-12-27
Affected Systems:
GNU inetutils 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-4862
GNU inetutils is a common network tool and server set.
GNU inetutils has a security vulnerability in the implementation of telneted, which can be exploited by malicious users to control the affected system.
This vulnerability is caused by a boundary error in the function "encrypt_keyid ()" (libtelnet/encrypt. c). You can send a specially crafted command to the server to cause a buffer overflow.
<* Source: FreeBSD telnetd service
Link: http://secunia.com/advisories/46239/
Http://git.savannah.gnu.org/cgit/inetutils.git/commit? Id = 665f1e73cdd9b38e2d2e11b8db9958a315935592
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnu.org