CVE-2005-0468 describes a heap-based buffer overflow in the env_opt_add function of various BSD-based Telnet clients, including NCSA Telnet. This vulnerability allows remote attackers to execute arbitrary code by sending responses with an excessive number of characters requiring escaping, leading to memory exhaustion. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) and a FAUCET Risk Score of 98/100, it represents a high-severity threat that is easily exploitable over the network without authentication, potentially leading to full compromise. While not listed in CISA's KEV catalog or showing active community discussion or media coverage, an ExploitDB entry (EDB-25303) confirms the existence of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
cCPE matchmatch criteria | cpe:2.3:a:ncsa:telnet:c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.