telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a telnet/tcp server failing (looping), service terminated error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Inetutils | Gnu | * | 2.3 (including) |
Inetutils | Ubuntu | bionic | * |
Inetutils | Ubuntu | focal | * |
Inetutils | Ubuntu | jammy | * |
Inetutils | Ubuntu | trusty | * |
Inetutils | Ubuntu | trusty/esm | * |
Inetutils | Ubuntu | upstream | * |
Inetutils | Ubuntu | xenial | * |