Page MenuHomeFreeBSD

telnetd: fix two-byte input crash
ClosedPublic

Authored by brooks on Sep 23 2022, 6:05 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Oct 24, 7:17 PM
Unknown Object (File)
Sep 24 2024, 10:21 AM
Unknown Object (File)
Sep 15 2024, 6:34 PM
Unknown Object (File)
Sep 5 2024, 8:00 PM
Unknown Object (File)
Sep 2 2024, 4:57 PM
Unknown Object (File)
Aug 30 2024, 9:04 PM
Unknown Object (File)
Aug 29 2024, 3:53 PM
Unknown Object (File)
Aug 8 2024, 12:58 PM
Subscribers

Details

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

There's also a fix for CVE-2020-10188 (https://github.com/cschuber/freebsd-telnet/commit/e76b51e91f6d9aa7b72ee6624c29b46ddce2a406). Do you want to commit that or should I?

This revision is now accepted and ready to land.Sep 24 2022, 4:15 AM

Next question. I maintain the extract of the FreeBSD telnet/telnetd on GH, of which telnetd is a port while telnet is in the repo should we choose to remove it as well. I've been toying with the idea of telnet and telnetd ports based on NetBSD. They will probably pay more attention to it than we might. Thoughts?

In D36680#832950, @cy wrote:

There's also a fix for CVE-2020-10188 (https://github.com/cschuber/freebsd-telnet/commit/e76b51e91f6d9aa7b72ee6624c29b46ddce2a406). Do you want to commit that or should I?

Please go ahead and commit that one. I'll wait to delete the build bits (D36620) and sources (D36621) until you do so the changes be be MFCd.

In D36680#832953, @cy wrote:

Next question. I maintain the extract of the FreeBSD telnet/telnetd on GH, of which telnetd is a port while telnet is in the repo should we choose to remove it as well. I've been toying with the idea of telnet and telnetd ports based on NetBSD. They will probably pay more attention to it than we might. Thoughts?

There's probably some sense in making a port of the NetBSD ones. Ours will continue to rot. On the client side, the OpenBSD version might be worth considering.

This revision was automatically updated to reflect the committed changes.