CVE-2018-20764

helpsystems boks: Sicherheitsluecke

criticalEPSS 1.2%

Affected

  • helpsystems/boks between 6.6.0..6.7.1

Description

A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

helpsystemsboks
6.6.0 – 6.7.1

Metrics

9.8
Source: nvd-v3
66.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-02-08 17:00 UTC

References & sources