From cfe888f14ac2cd32f1de7b38cd383c2cb63880fc Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 7 Apr 2020 22:36:12 +0200 Subject: Track inetutils under CVE-2020-10188 The respective functions in src:inetutils in utility.c correspond to very similar code in netkit. Further investigation pending so far if src:inetutils is due to as well affected by the CVE-2020-10188. The same CVE could be used probably here due to same logic implemented in the nextitem function. --- data/CVE/list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list b/data/CVE/list index 79009b662b..96900b7e34 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -3641,6 +3641,7 @@ CVE-2020-10190 (An issue was discovered in MunkiReport before 5.3.0. An authenti CVE-2020-10189 (Zoho ManageEngine Desktop Central before 10.0.474 allows remote code e ...) NOT-FOR-US: Zoho ManageEngine CVE-2020-10188 (utility.c in telnetd in netkit telnet through 0.17 allows remote attac ...) + - inetutils (bug #956084) - netkit-telnet 0.17-18woody2 (bug #953477) - netkit-telnet-ssl 0.17.17+0.1-2woody3 (bug #953478) NOTE: https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html -- cgit v1.2.3