Re: Stack-based Buffer Overflow in telnet/tn3270.c (settranscom)

Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Fri, 23 Jan 2026 23:23:37 +0100
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <[email protected]>
Thank you for review.  How did you build with TN3270 support?  Does
anyone know of anyone building with -DTN3270?  I tried ./configure
CFLAGS=-DTN3270 and it doesn't build for me.  Does it build on any
reasonable platform?

One approach here is to remove everything within '#ifdef TN3270' if this
code is unmaintained, not working, and comes with security concerns.

Would anyone mis the TN3270 functionality?  Is there any way we can test
the functionality to gain confidence in it?

Making all in telnet
make[2]: Entering directory '/home/jas/src/inetutils/telnet'
  CC       commands.o
commands.c: In function 'bye':
commands.c:1658:7: error: implicit declaration of function 'SetIn3270' [-Wimplicit-function-declaration]
 1658 |       SetIn3270 ();             /* Get out of 3270 mode */
      |       ^~~~~~~~~
commands.c: In function 'status':
commands.c:2414:30: error: too many arguments to function 'getpgrp'
 2414 |                   getpid (), getpgrp (getpid ()));
      |                              ^~~~~~~
In file included from ../lib/unistd.h:40,
                 from /usr/include/x86_64-linux-gnu/bits/sigstksz.h:24,
                 from /usr/include/signal.h:328,
                 from ../lib/signal.h:52,
                 from /usr/include/x86_64-linux-gnu/sys/param.h:28,
                 from commands.c:51:
/usr/include/unistd.h:656:16: note: declared here
  656 | extern __pid_t getpgrp (void) __THROW;
      |                ^~~~~~~
make[2]: *** [Makefile:2643: commands.o] Error 1

/Simon

Veper X <[email protected]> writes:

> Dear GNU Inetutils Maintainers,
>
> I would like to report a stack-based buffer overflow vulnerability identified in the `telnet` client source code, specifically within the TN3270
> emulation support.
>
> **Vulnerability Details:**
>
> - **File:** `telnet/tn3270.c`
> - **Function:** `settranscom(int argc, char *argv[])`
> - **Line:** 448 (in recent git master)
>
> **Description:**
> The function `settranscom` copies command-line arguments into a global static buffer `tline` which has a fixed size of 200 bytes. The copy
> is performed using `strcpy` and `strcat` without checking the length of the source strings (`argv` elements).
>
> ```c
> /* telnet/tn3270.c */
> char tline[200];
> ...
> int settranscom (int argc, char *argv[])
> {
>   ...
>   transcom = tline;
>   strcpy (transcom, argv[1]);  /* VULNERABLE: Unbounded copy */
>   for (i = 2; i < argc; ++i)
>     {
>       strcat (transcom, " ");
>       strcat (transcom, argv[i]); /* VULNERABLE: Unbounded concatenation */
>     }
>   return 1;
> }
> ```
>
> **Impact:**
> If `inetutils` is compiled with TN3270 support enabled (via `#define TN3270`), an attacker or local user can crash the application or
> potentially achieve code execution by supplying an overly long argument to the `transcom` command (or whichever mechanism invokes
> `settranscom`).
>
> While we observed that TN3270 support appears to be disabled by default in standard builds, the vulnerable code remains in the
> codebase and poses a risk to anyone enabling this feature.
>
> **Recommendation:**
> We suggest replacing `strcpy` / `strcat` with safer alternatives like `snprintf` to ensure the data does not exceed the bounds of `tline` (200
> bytes).
>
> Thank you for your time and maintenance of GNU Inetutils.
>
> Best regards,
> Peikai Li
>
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmlz9OkUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFoiMcAQDISm+zMk1u
wulgz1vkyr1zVs3RZ98WjDODx03pCKby+gEAkU2bgWRYWAP0iWFigXhRzoNcFdMY
KS+hq/vYd3DH4QU=
=SFEf
-----END PGP SIGNATURE-----