Re: Security: ftpd vulnerability in GNU inetutils
Oculytic <[email protected]> Sun, 12 Apr 2026 18:48:10 +0100
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <CAJfnK9MGaaWDjLzdgOujsmd0wL8FfRu2rWCLOrNnBgg2qo_k7Q@mail.gmail.com> |
--000000000000df8d61064f46f8ff Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Sorry, I did not know the 'bugs' email linked directly to the public list. I will email you directly with more details. On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk <[email protected]= > wrote: > Oculytic <[email protected]> writes: > > > I've attached a full writeup with root cause analysis, affected code > > locations. > > > > I'd like to propose a 30-day disclosure window from today's date. I'm > happy > > to work with you on a fix - the writeup includes suggested remediation > > approaches (replacing signal/longjmp with a flag-based or self-pipe > > approach). > > > > I also plan to request a CVE ID from MITRE and coordinate with the > distros > > list once a patch is ready. Please let me know if you'd prefer a > different > > timeline or process. > > > > Please confirm receipt when you can. > > This is a public list [1]. > > Given that the attached writeup looks like it was copy pasted from an > LLM, I would appreciate if you could send reproduction steps before I > rush to look at it. > > Collin > > [1] https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg00000.htm= l > --000000000000df8d61064f46f8ff Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Sorry, I did not know the 'bugs' email linked dire= ctly to the public list. I will email you directly with more details.</div>= <br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class= =3D"gmail_attr">On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk <<a = href=3D"mailto:[email protected]">[email protected]</a>> wrote= :<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.= 8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Oculytic <<= a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</= a>> writes:<br> <br> > I've attached a full writeup with root cause analysis, affected co= de<br> > locations.<br> ><br> > I'd like to propose a 30-day disclosure window from today's da= te. I'm happy<br> > to work with you on a fix - the writeup includes suggested remediation= <br> > approaches (replacing signal/longjmp with a flag-based or self-pipe<br= > > approach).<br> ><br> > I also plan to request a CVE ID from MITRE and coordinate with the dis= tros<br> > list once a patch is ready. Please let me know if you'd prefer a d= ifferent<br> > timeline or process.<br> ><br> > Please confirm receipt when you can.<br> <br> This is a public list [1].<br> <br> Given that the attached writeup looks like it was copy pasted from an<br> LLM, I would appreciate if you could send reproduction steps before I<br> rush to look at it.<br> <br> Collin<br> <br> [1] <a href=3D"https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg= 00000.html" rel=3D"noreferrer" target=3D"_blank">https://lists.gnu.org/arch= ive/html/bug-inetutils/2026-04/msg00000.html</a><br> </blockquote></div> --000000000000df8d61064f46f8ff--