検索

2.7までのGNU inetutilsに含まれるtelnetdに、細工した環境変数を送信するだけで認証を回避して特権ユーザーでのログインが可能な脆弱性が発見されらしい。CVE-2026-24061。いまどきtelnetdをThe Internetに露出している人はそうそういないはずとはいえ、なかなか興味深いので調べてみたところ。telnetdがexecv()で呼び出す/usr/bin/loginのコマンドラインオプションをうまく使うことでそういうことができてしまうようで、正直興奮した。 https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/ #CVE #GNU #inetutils #login #telnetd #サイバーセキュリティ #セキュリティ #情報セキュリティ #脆弱性
返信 0 · Renote 1
Status update on the whole RHEL iperf3 saga... The patch by @[email protected] from @[email protected] has been merged into @[email protected] Stream 8! The c9s patch state is a bit different as the maintainer would rather backport than rebase. This comes after Red Hat's Product Security team rated CVE-2023-38403 as Important, the second highest rating. https://access.redhat.com/security/cve/cve-2023-38403 #redhat #rhel #centos #centosstream #community #cve #vulnerability #alma #almalinux #contribution #contribute #contributing
返信 0 · Renote 1