CVE-2004-0640: Critical severity Netkit Linux Netkit vulnerability
Published Jul 9, 2004
·Updated
Format string vulnerability in the SSLsetverify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.
Affected Software
3 affected components
Netkit Linux Netkit=0.17
Netkit Linux Netkit=0.17.17
SSLtelnetd Secure Telnet=0.13.1
Remediation
Patch Available
Event History
Jul 9, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0640?
CVE-2004-0640 has been classified with a high severity due to the potential for remote code execution.
2
How do I fix CVE-2004-0640?
To fix CVE-2004-0640, update to fixed versions of the software, specifically those beyond 0.13 for SSLtelnet daemon.
3
What systems are impacted by CVE-2004-0640?
CVE-2004-0640 affects version 0.13 of the SSLtelnet daemon and versions 0.17 and 0.17.17 of Linux Netkit.
4
What type of vulnerability is CVE-2004-0640?
CVE-2004-0640 is a format string vulnerability that allows attackers to execute arbitrary code remotely.
5
Who can be targeted by CVE-2004-0640?
CVE-2004-0640 can be exploited by remote attackers aiming to compromise systems running the affected versions of SSLtelnet or Linux Netkit.