SynopsisThe remote Debian host is missing a security update.
DescriptionNOTE: This DLA was intially sent on 2020-04-14 but for reasons unknown failed to reach the mailing list. It is being re-sent now to ensure that it appears in the mailing list archive. No new version of inetutils has been published since version 2:22.214.171.124.3a460-3+deb8u1 described in the original advisory.
A vulnerability was discovered in the telnetd component of inetutils, a collection of network utilities. Execution of arbitrary remote code was possible through short writes or urgent data.
For Debian 8 'Jessie', this problem has been fixed in version 2:126.96.36.199.3a460-3+deb8u1.
We recommend that you upgrade your inetutils packages.
NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpgrade the affected packages.