Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-0468

42
FAUCET Score

CVE-2005-0468 describes a heap-based buffer overflow in the env_opt_add function of various BSD-based Telnet clients, including NCSA Telnet. This vulnerability allows remote attackers to execute arbitrary code by sending responses with an excessive number of characters requiring escaping, leading to memory exhaustion. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) and a FAUCET Risk Score of 98/100, it represents a high-severity threat that is easily exploitable over the network without authentication, potentially leading to full compromise. While not listed in CISA's KEV catalog or showing active community discussion or media coverage, an ExploitDB entry (EDB-25303) confirms the existence of public exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
cCPE matchmatch criteria
cpe:2.3:a:ncsa:telnet:c:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
27.07%
Probability of exploitation in next 30 days
EPSS Percentile
97.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-25303 · Mar 28, 2005
This CVE's current EPSS score of 0.2707 is in the 96th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: telnet-1:0.17-26.EL3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: krb5-0:1.2.7-42
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: telnet-1:0.17-31.EL4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: krb5-0:1.3.4-12
View patch

Vendor Advisories (1)

redhatCVE-2005-0468Important

security flaw

Mar 28, 2005

References

ftp.freebsd.org / pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc
Vendor Advisory
patches.sgi.com / support/free/security/advisories/20050405-01-P
Patch
distro.conectiva.com.br / atualizacoes
secunia.com / advisories/14745
secunia.com / advisories/17899
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9640
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
web.mit.edu / kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt
PatchVendor Advisory
debian.de / security/2005/dsa-731
debian.org / security/2005/dsa-703
PatchVendor Advisory
idefense.com / application/poi/display
Vendor Advisory
kb.cert.org / vuls/id/341908
US Government Resource
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2005-327.html
PatchVendor Advisory
redhat.com / support/errata/RHSA-2005-330.html
PatchVendor Advisory
securityfocus.com / bid/12919
ubuntulinux.org / usn/usn-224-1