Re: Telnetd Vulnerability Report

Ron Ben Yizhak <[email protected]> Mon, 16 Feb 2026 14:03:01 +0200
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <CAB1hGqRGf0Nrktr6gHyiwt6z-OyUt1raZEs1zg27SvzqjTWofQ@mail.gmail.com>
--000000000000296acb064aefbdab
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

Thank you for handling my report and fixing the vulnerability. As this
finding was done as part of my job at SafeBreach, it is very important for
us that SafeBreach will be mentioned in the patch.
Could you please change the THANKS and NEWS.md file to say Ron Ben
Yizhak@SafeBreach instead of Ron Ben Yizhak?

Also, when will a CVE be assigned for this vulnerability?
Thank you,
Ron Ben Yizhak

On Sun, Feb 15, 2026 at 7:21=E2=80=AFPM Erik Auerswald <[email protected]=
i-kl.de>
wrote:

> Hi Simon,
>
> On Sun, Feb 15, 2026 at 04:36:56PM +0100, Simon Josefsson wrote:
> > Erik Auerswald <[email protected]> writes:
> >
> > > I plan to commit and push the attached patch in a few days to address
> > > this vulnerability, unless there are reasonable objections.
> >
> > Thanks -- I wish we could implement the --accept-env approach and make
> > the default not set any environment variables at all, but I don't have
> > cycles to work on that.  Anyone else?
>
> Me neither.
>
> > Your patch seems to close this vulnerability report in a most minimal
> > way, so IMHO we should apply it.
>
> I have just applied it.
>
> Cheers,
> Erik
>

--000000000000296acb064aefbdab
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>Thank you for handling my report an=
d fixing the vulnerability. As this finding was done as part of my job at S=
afeBreach, it is very important for us that SafeBreach will be mentioned in=
 the patch.</div><div>Could you please change the THANKS and NEWS.md file t=
o say Ron Ben Yizhak@SafeBreach instead of Ron Ben Yizhak?</div><div><br></=
div><div>Also, when will a CVE be assigned for this vulnerability?<br>Thank=
 you,<br>Ron Ben Yizhak</div></div><br><div class=3D"gmail_quote gmail_quot=
e_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Feb 15, 2026 at =
7:21=E2=80=AFPM Erik Auerswald &lt;<a href=3D"mailto:[email protected]=
l.de">[email protected]</a>&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex">Hi Simon,<br>
<br>
On Sun, Feb 15, 2026 at 04:36:56PM +0100, Simon Josefsson wrote:<br>
&gt; Erik Auerswald &lt;<a href=3D"mailto:[email protected]" targe=
t=3D"_blank">[email protected]</a>&gt; writes:<br>
&gt; <br>
&gt; &gt; I plan to commit and push the attached patch in a few days to add=
ress<br>
&gt; &gt; this vulnerability, unless there are reasonable objections.<br>
&gt; <br>
&gt; Thanks -- I wish we could implement the --accept-env approach and make=
<br>
&gt; the default not set any environment variables at all, but I don&#39;t =
have<br>
&gt; cycles to work on that.=C2=A0 Anyone else?<br>
<br>
Me neither.<br>
<br>
&gt; Your patch seems to close this vulnerability report in a most minimal<=
br>
&gt; way, so IMHO we should apply it.<br>
<br>
I have just applied it.<br>
<br>
Cheers,<br>
Erik<br>
</blockquote></div>

--000000000000296acb064aefbdab--