CVE-2020-10188

CVE-2020-10188

Publicada el · Actualizada el

25Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 74%
probabilidad de explotación
74%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
1 producto
Red Hat Enterprise Linux 5
workaround: When in enforcing mode, SELinux as configured in Red Hat Enterprise Linux provides some mitigation against an exploit for telnet-server, because it limits the kind of operations it can perform and programs that can be run from the telnet-server's…
Corregido
16 productos (75 componentes)
Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux Server E4S (v. 7.6) · Red Hat Enterprise Linux Server E4S (v. 7.7) · Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Workstation (v. 6) · y otros 11
No afectado
10 productos (74 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux AppStream E4S (v. 8.0) · Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Server (v. 7) · y otros 5
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Productos afectados
n/a · n/a