CVE-2022-39028
Summary
| CVE | CVE-2022-39028 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-30 05:15:00 UTC |
| Updated | 2023-09-27 20:10:00 UTC |
| Description | telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3205-1] inetutils security update |
MLIST |
lists.debian.org |
|
| [BUG][PATCH] Someone described a remote DoS Vulnerability in telnetd (de |
MISC |
lists.gnu.org |
|
| 2-byte DoS in freebsd-telnetd / netbsd-telnetd / netkit-telnetd / inetutils-telnetd / telnetd in Kerberos Version 5 Applications - Binary Golf Grand Prix 3 - IT Security Research by Pierre |
MISC |
pierrekim.github.io |
|
| debian/pkgs/inetutils.git - Debian inetutils packaging |
MISC |
git.hadrons.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181028 Debian Security Update for inetutils (CVE-2022-39028)
- 181247 Debian Security Update for inetutils (DLA 3205-1)
- 199675 Ubuntu Security Notification for Inetutils Vulnerabilities (USN-6304-1)
- 752639 SUSE Enterprise Linux Security Update for krb5-appl (SUSE-SU-2022:3471-1)
- 752730 SUSE Enterprise Linux Security Update for telnet (SUSE-SU-2022:3783-1)
- 752735 SUSE Enterprise Linux Security Update for telnet (SUSE-SU-2022:3735-1)