oss-sec mailing list archives
Re: CVE-2026-28372: Telnetd Vulnerability Report
From: Guillem Jover <guillem () debian org>
Date: Sat, 7 Mar 2026 00:37:40 +0100
Hi! On Sat, 2026-03-07 at 00:17:55 +0100, Salvatore Bonaccorso wrote:
On Fri, Mar 06, 2026 at 04:39:23PM +0100, Guillem Jover wrote:I'm not part of the Debian Security Team (I just maintain the inetutils package in Debian), but I think they assigned a CVE because there didn't seem to be one coming from upstream. I guess the expectation would be that if there's a new CVE to be assigned that would be handled by upstream, but if it's needed and it's not forthcoming they might assign another one? (Although the easier way forward would be to reuse the existing one, and issue an update for the DSA.)I just need to clarify one thing here: The CVE was not assigned by the Debian CNA, but as there was no CVE assigned by the issue reported by Ron, I requested one from MITRE. There was none assigned in time when we released the DSA, and at that point TTBOMK the more general issue/root cause indication by Justin Swartz was not known. So the CVE request to MITRE was done specifically as for the issue found by Ron.
Right, sorry, as it seems like I forgot about this (where I was even CCed in later emails mentioning this)! Thanks, Guillem
Current thread:
- Re: Telnetd Vulnerability Report, (continued)
- Re: Telnetd Vulnerability Report Justin Swartz (Mar 07)
- Re: Telnetd Vulnerability Report Solar Designer (Mar 08)
- Re: Telnetd Vulnerability Report Justin Swartz (Mar 08)
- Re: Telnetd Vulnerability Report Solar Designer (Mar 08)
- Re: Re: Telnetd Vulnerability Report Pat Gunn (Mar 07)
- CVE-2026-28372: Telnetd Vulnerability Report Guillem Jover (Feb 27)
- Re: CVE-2026-28372: Telnetd Vulnerability Report Solar Designer (Mar 06)
- Re: CVE-2026-28372: Telnetd Vulnerability Report Guillem Jover (Mar 06)
- Re: CVE-2026-28372: Telnetd Vulnerability Report Salvatore Bonaccorso (Mar 07)
- Re: CVE-2026-28372: Telnetd Vulnerability Report Guillem Jover (Mar 07)
- Re: Re: Telnetd Vulnerability Report kf503bla (Feb 24)
- Re: Telnetd Vulnerability Report Solar Designer (Feb 24)
- Re: Telnetd Vulnerability Report Lyndon Nerenberg (VE7TFX/VE6BBM) (Feb 24)
- Re: Telnetd Vulnerability Report Vincent Lefevre (Feb 24)
- Message not available
- Re: Telnetd Vulnerability Report kf503bla (Feb 25)
- Re: Telnetd Vulnerability Report Solar Designer (Feb 25)
- Re: Telnetd Vulnerability Report Steffen Nurpmeso (Feb 25)
- Re: Telnetd Vulnerability Report Marco Moock (Feb 25)
- Re: Telnetd Vulnerability Report Steffen Nurpmeso (Feb 25)
