Re: Security: ftpd vulnerability in GNU inetutils
Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Mon, 13 Apr 2026 09:34:54 +0200
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable I don't see a lot of reasons to not have details and discussion in public, most of InetUtils is ancient code and there is surely lots of problematic things in it (I think we've just seen the beginnings of a vulnerability report flood here...) -- more public code review and discussion seems fine to me. Coordinating analysis and resulting code fixes with *BSD and other actively maintained implementations would also be nice. Alas, I don't have a lot of cycles so will try to focus on release management so we have a working method to get fixes published. The v2.8 release is over-due, and I will prioritze getting that out first. /Simon Oculytic <[email protected]> writes: > Sorry, I did not know the 'bugs' email linked directly to the public list. > I will email you directly with more details. > > On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk <[email protected]= om> wrote: > >> Oculytic <[email protected]> writes: >> >> > I've attached a full writeup with root cause analysis, affected code >> > locations. >> > >> > I'd like to propose a 30-day disclosure window from today's date. I'm >> happy >> > to work with you on a fix - the writeup includes suggested remediation >> > approaches (replacing signal/longjmp with a flag-based or self-pipe >> > approach). >> > >> > I also plan to request a CVE ID from MITRE and coordinate with the >> distros >> > list once a patch is ready. Please let me know if you'd prefer a >> different >> > timeline or process. >> > >> > Please confirm receipt when you can. >> >> This is a public list [1]. >> >> Given that the attached writeup looks like it was copy pasted from an >> LLM, I would appreciate if you could send reproduction steps before I >> rush to look at it. >> >> Collin >> >> [1] https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg00000.ht= ml >> --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmncnJ4UHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFouzjAQCttteyy4UF YLFTYg5VMTUi/3JfgJujLvF8pULfi/q0FgEA9OAR8xwLi7TiYPCqfvj/DkKXim43 RrKQbUYuOyEoHAs= =FFWc -----END PGP SIGNATURE----- --=-=-=--