PT-2022-4813 · Mit+4 · Mit Krb5-Appl+4

Alexandre Torres

+3

·

Published

2022-08-27

·

Updated

2025-09-28

·

CVE-2022-39028

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Inetutils versions through 2.3 MIT krb5-appl versions through 1.0.3
Description The issue is related to a NULL pointer dereference in the telnetd application, which can occur via specific byte sequences, such as 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash, but the telnet service would remain available through inetd. However, if the telnetd application experiences many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error.
Recommendations For GNU Inetutils versions through 2.3, consider disabling the telnetd application until a patch is available to prevent potential denial-of-service attacks. For MIT krb5-appl versions through 1.0.3, restrict access to the telnet service to minimize the risk of exploitation, as the affected code was removed from the supported MIT Kerberos 5 product many years ago. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2022-05813
CVE-2022-39028
DLA-3205-1
MGASA-2022-0394
MGASA-2022-0460
OESA-2024-1354
OESA-2024-1359
OESA-2024-1360
OESA-2024-1361
OESA-2024-1362
OESA-2024-1363
OPENSUSE-SU-2022_3783-1
OPENSUSE-SU-2024:12436-1
SUSE-SU-2022:3471-1
SUSE-SU-2022:3735-1
SUSE-SU-2022:3783-1
SUSE-SU-2022_3471-1
SUSE-SU-2022_3735-1
SUSE-SU-2022_3783-1
USN-6304-1
USN-7781-1

Affected Products

Gnu Inetutils
Linuxmint
Mit Krb5-Appl
Suse
Ubuntu