Re: Local Privilege Escalation via telnetd debug_open() and printsub()
Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Tue, 17 Mar 2026 08:40:28 +0100
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain Collin Funk <[email protected]> writes: > Justin Swartz <[email protected]> writes: > >> Greetings, >> >> I've identified two bugs in the debugging support provided by >> telnetd that may be combined to achieve local privilege escalation >> or arbitrary file corruption. Thank you Justin! Keep'em coming. > The lack of sanitization is fine. It is only a problem when combined > with the incorrect behavior of that link being followed. I agree. > I submitted a pull request to address that [1]. > [1] https://codeberg.org/inetutils/inetutils/pulls/20 I'm not completely opposed to solving it like this, but it feels like a hack. Why are we opening a hard-coded path file like this in the first place? Couldn't we use syslog for logging here? That's what ftpd --debug uses. Did anyone review other telnetd implementations? NetKit, BSD, Solaris, etc. Is --debug widely and consistently implemented? /Simon --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmm5BWwUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFonJhAQDdHuXI34wc Jp3aC6m/vJL6ViyDS9f1aV3YdDs7fQGm0AD/e8PRYk+l1oL0y+BOshBMWOutZQZx zr0FF/yeMkzjtQk= =Zuhi -----END PGP SIGNATURE----- --=-=-=--