Title : Multiple Telnet Clients Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0300 CVE ID : CVE-2005-0468 - CVE-2005-0469 CWE ID : CWE-
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-03-30
Technical Description
Two vulnerabilities were identified in several Telnet clients, which may be exploited by attackers to execute arbitrary commands.
- The first flaw is due to a heap overflow error in the "env_opt_add()" function (telnet.c), which may be exploited to execute arbitrary commands in the context of the user who launched the telnet client.
- The second vulnerability is due to a buffer overflow error when handling LINEMODE suboptions and processing replies containing a large number of SLC (Set Local Character) commands, which may be exploited to execute arbitrary commands in the context of the user who launched the telnet client.