Release of GNU inetutils 2.5 addressing vulnerabilities in suid applications

After 14 months of development, the release of GNU inetutils 2.5 has been finalized, featuring a collection of network programs, most of which have been ported from BSD systems. In particular, it includes inetd and syslogd, servers and clients for ftp, telnet, rsh, rlogin, tftp, and talk, as well as common utilities like ping, ping6, traceroute, whois, hostname, dnsdomainname, ifconfig, logger, etc.

The new version addresses a vulnerability (CVE-2023-40303) in the suid programs ftpd, rcp, rlogin, rsh, rshd, and uucpd, caused by the absence of checks on the return values from the setuid(), setgid(), seteuid(), and setguid() functions. This vulnerability can be exploited to create conditions where a set*id() call does not drop privileges, allowing the application to continue running with elevated privileges and perform operations intended for a non-privileged user. For example, processes such as ftpd, uucpd, and rshd, started with root privileges, would continue to use root privileges after a failed set*id() call when user sessions are initiated.

In addition to fixing the vulnerability and minor bugs, the new version of the ping6 utility adds support for ICMPv6 messages with information about the target host being unreachable ('destination unreachable', RFC 4443).

    Source: opennet.ru

    Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster