Lucene search

K
cveMitreCVE-2004-0640
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0640

2004-08-0604:00:00
mitre
web.nvd.nist.gov
52
ssltelnetd
telnetd.c
ssl_set_verify
format string vulnerability
cve-2004-0640
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.027

Percentile

90.5%

Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.

Affected configurations

Nvd
Node
netkitlinux_netkitMatch0.17
OR
netkitlinux_netkitMatch0.17.17
OR
ssltelnetdsecure_telnetMatch0.13.1
VendorProductVersionCPE
netkitlinux_netkit0.17cpe:2.3:a:netkit:linux_netkit:0.17:*:*:*:*:*:*:*
netkitlinux_netkit0.17.17cpe:2.3:a:netkit:linux_netkit:0.17.17:*:*:*:*:*:*:*
ssltelnetdsecure_telnet0.13.1cpe:2.3:a:ssltelnetd:secure_telnet:0.13.1:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.027

Percentile

90.5%