Re: Local Privilege Escalation via telnetd debug_open() and printsub()
Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Tue, 24 Mar 2026 17:17:22 +0100
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Collin Funk <[email protected]> writes: >> I don't think the proposal to dump the entire protocol into syslog >> seem like a great idea either, which would require substantial >> sanitization. Instead for Debian I went with a relatively simple >> change from using =AB/tmp/telnet-debug=BB to =AB/run/telnet/debug.<PID>= =BB, >> and made telnetd print the pathname used on the telnet session. >> >> I suppose an alternative could be to let the telnetd user specify a >> filename to use. But the /run switch seems good enough to me. > > I don't like the syslog idea either. > > I kind of feel like the option should just be removed. I can't find any > users of 'telnetd --debug' or 'telnetd -D' on GitHub or Debian code > search. If someone needs to debug telnet Wireshark is available pretty > much everywhere. I think it would be fine to just remove this (anti-)feature. However, ftpd supports --debug to send things to syslog. Is it is similarily vulnerable? Assuming that attackers can add '--debug' to telnetd invocation, and also be able to read syslog content, doesn't seem all that reasonable to me. /Simon --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmnCuRIUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFonJAAQCDpWJWTpMx 1MSh4EbNoqguZpA8MIUIAd0wBPQLZviHdAD/YAV+A67ZLVkAdTfz/bvhCm8Xnfs0 WEhiB4/RvxRkUAA= =Zxvx -----END PGP SIGNATURE----- --=-=-=--