Re: Local Privilege Escalation via telnetd debug_open() and printsub()

Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Tue, 24 Mar 2026 17:17:22 +0100
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <[email protected]>
--=-=-=
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

Collin Funk <[email protected]> writes:

>> I don't think the proposal to dump the entire protocol into syslog
>> seem like a great idea either, which would require substantial
>> sanitization. Instead for Debian I went with a relatively simple
>> change from using =AB/tmp/telnet-debug=BB to =AB/run/telnet/debug.<PID>=
=BB,
>> and made telnetd print the pathname used on the telnet session.
>>
>> I suppose an alternative could be to let the telnetd user specify a
>> filename to use. But the /run switch seems good enough to me.
>
> I don't like the syslog idea either.
>
> I kind of feel like the option should just be removed. I can't find any
> users of 'telnetd --debug' or 'telnetd -D' on GitHub or Debian code
> search. If someone needs to debug telnet Wireshark is available pretty
> much everywhere.

I think it would be fine to just remove this (anti-)feature.

However, ftpd supports --debug to send things to syslog.  Is it is
similarily vulnerable?

Assuming that attackers can add '--debug' to telnetd invocation, and
also be able to read syslog content, doesn't seem all that reasonable to
me.

/Simon

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmnCuRIUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFonJAAQCDpWJWTpMx
1MSh4EbNoqguZpA8MIUIAd0wBPQLZviHdAD/YAV+A67ZLVkAdTfz/bvhCm8Xnfs0
WEhiB4/RvxRkUAA=
=Zxvx
-----END PGP SIGNATURE-----
--=-=-=--