Vulnerabilities > CVE-2004-0640

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
netkit
ssltelnetd
critical
nessus

Summary

Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.

Vulnerable Configurations

Part Description Count
Application
Netkit
2
Application
Ssltelnetd
1

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-529.NASL
    description'b0f
    last seen2020-06-01
    modified2020-06-02
    plugin id15366
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15366
    titleDebian DSA-529-1 : netkit-telnet-ssl - format string
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_SSLTELNET_0131.NASL
    descriptionSSLtelnet contains a format string vulnerability that could allow remote code execution and privilege escalation.
    last seen2020-06-01
    modified2020-06-02
    plugin id12617
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12617
    titleFreeBSD : Format string vulnerability in SSLtelnet (4aec9d58-ce7b-11d8-858d-000d610a3b12)