CVE-2005-0468
krb4 - buffer overflows
EPSS 27.1%
描述
Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.
如何修補 CVE-2005-0468
要修補 CVE-2005-0468,請將受影響套件升級到下列已修補版本。
- Debian/krb4—升級至 1.1-8-2.4 或更新版本
- Debian/krb5—升級至 1.3.6-2 或更新版本
- Debian/krb5—升級至 1.2.4-5woody8 或更新版本
CVE-2005-0468 正在被利用嗎?
中等 — EPSS 為 27.1%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.1-8-2.4
- from 0, < 1.3.6-2
- from 0, < 1.2.4-5woody8