{"id":162791,"date":"2026-02-25T17:11:54","date_gmt":"2026-02-25T15:11:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme"},"modified":"2026-02-25T17:11:54","modified_gmt":"2026-02-25T15:11:54","slug":"seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme","title":{"rendered":"Una serie de nuevas vulnerabilidades en telnetd, que permiten obtener privilegios de root en el sistema.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Tras la vulnerabilidad detectada a finales de enero que permit\u00eda conectarse como usuario root sin verificar la contrase\u00f1a, se identificaron varios m\u00e9todos de elevaci\u00f3n de privilegios en el servidor telnetd del conjunto GNU InetUtils, resultado de la soluci\u00f3n incompleta de la vulnerabilidad en 1999 (CVE-1999-0073).     <\/p>\n<p>Las vulnerabilidades se deben a la capacidad del telnetd para transmitir variables de entorno desde el cliente al servidor a trav\u00e9s de la opci\u00f3n ENVIRON. Estas variables de entorno se establecen y procesan en el contexto del proceso telnetd y se transmiten a sus procesos hijos, incluido el proceso \/bin\/login que se ejecuta con privilegios de root. La vulnerabilidad CVE-1999-0073 permit\u00eda al cliente telnet transmitir la variable de entorno LD_LIBRARY_PATH, cuya configuraci\u00f3n lleva a la carga de la biblioteca compartida especificada por el usuario al iniciar el proceso login. Si se permite cargar archivos en un sistema que soporte la conexi\u00f3n por el protocolo telnet, un atacante puede cargar una biblioteca dise\u00f1ada espec\u00edficamente y organizar su carga con privilegios de root.      <\/p>\n<p>En telnetd del paquete GNU InetUtils, se solucion\u00f3 una vulnerabilidad al prohibir las variables de entorno peligrosas mediante la filtraci\u00f3n de patrones \u00abLD_\u00bb, \u00abLIBPATH\u00bb, \u00abENV\u00bb, \u00abIFS\u00bb y \u00ab_RLD_\u00bb. Sin embargo, la variable de entorno \u00abCREDENTIALS_DIRECTORY\u00bb no fue bloqueada, y se procesa al iniciar \/usr\/bin\/login. Con esta variable de entorno, un usuario pod\u00eda cambiar el directorio de configuraci\u00f3n de credenciales y colocar en el nuevo directorio un archivo login.noauth con el valor \u00abyes\u00bb, lo que activaba el inicio de sesi\u00f3n sin contrase\u00f1a (similar a pasar la opci\u00f3n \u00ab-f\u00bb al proceso login). Esta configuraci\u00f3n afecta a todos los usuarios, incluyendo root.     <\/p>\n<p>El ataque consiste en que un usuario sin privilegios cree un subdirectorio en su directorio home, cargue en \u00e9l el archivo login.noauth e intente iniciar sesi\u00f3n estableciendo la variable de entorno \u00abCREDENTIALS_DIRECTORY=directorio creado\u00bb y pasando la variable de entorno \u00abUSER=root\u00bb (en telnet existe un modo de conexi\u00f3n autom\u00e1tica en el que el nombre de usuario no se toma de la l\u00ednea de comandos, sino que se pasa a trav\u00e9s de la variable de entorno USER). Ejemplo de exploit.    <\/p>\n<p>Se ha identificado otro m\u00e9todo para obtener acceso root a trav\u00e9s de telnetd, relacionado con la manipulaci\u00f3n de las variables de entorno OUTPUT_CHARSET y LANGUAGE, procesadas por la biblioteca GNU gettext, as\u00ed como la variable de entorno GCONV_PATH, utilizada en glibc. Al establecer las variables de entorno OUTPUT_CHARSET y LANGUAGE, el atacante puede activar en gettext la funcionalidad de conversi\u00f3n de juegos de caracteres que llama a la funci\u00f3n iconv_open(). A su vez, al ejecutar la funci\u00f3n iconv_open() al cargar el archivo de configuraci\u00f3n gconv-modules, la ruta se calcula teniendo en cuenta la variable de entorno GCONV_PATH. Mediante la sustituci\u00f3n del archivo gconv-modules, se puede organizar la carga de una biblioteca compartida personalizada durante la salida de una cadena localizada del proceso login.                <\/p>\n<p>Los identificadores CVE para estas vulnerabilidades a\u00fan no han sido asignados. Se est\u00e1 considerando como m\u00e9todo de protecci\u00f3n la implementaci\u00f3n de una lista blanca de valores permitidos (\u00abTERM\u00bb, \u00abDISPLAY\u00bb, \u00abUSER\u00bb, \u00abLOGNAME\u00bb y \u00abPOSIXLY_CORRECT\u00bb), bloqueando todas las dem\u00e1s variables de entorno, de manera similar a c\u00f3mo se manejan las variables de entorno en OpenSSH. Las vulnerabilidades han sido confirmadas en el paquete GNU InetUtils, implementaci\u00f3n. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-los-angeles\/\" title=\"servidores\" data-wpil-keyword-link=\"linked\">servidores<\/a> En Rocky Linux 9 se distribuye una versi\u00f3n modificada de telnetd que no es vulnerable, en la que, en lugar de filtrar las variables de entorno peligrosas, se ha implementado una comprobaci\u00f3n mediante la lista blanca. La filtraci\u00f3n mediante la lista blanca tambi\u00e9n se ha implementado en el telnetd que forma parte de FreeBSD. En OpenBSD, telnetd fue excluido del sistema en 2005.<br \/>\n<br \/>Fuente: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64869\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u043a\u043e\u043d\u0446\u0435 \u044f\u043d\u0432\u0430\u0440\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0448\u0435\u0439 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043f\u043e\u0434 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c root \u0431\u0435\u0437 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u0430\u0440\u043e\u043b\u044f, \u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 telnetd \u0438\u0437 \u043d\u0430\u0431\u043e\u0440\u0430 GNU InetUtils \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439, \u0441\u0442\u0430\u0432\u0448\u0438\u0445 \u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u0435\u043c \u043d\u0435\u043f\u043e\u043b\u043d\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 1999 \u0433\u043e\u0434\u0443 (CVE-1999-0073). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432\u044b\u0437\u0432\u0430\u043d\u044b \u043d\u0430\u043b\u0438\u0447\u0438\u0435\u043c \u0432 telnetd \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u043c \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u043e\u043f\u0446\u0438\u0438 ENVIRON. \u041f\u043e\u0434\u043e\u0431\u043d\u044b\u0435 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-162791","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u043a\u043e\u043d\u0446\u0435 \u044f\u043d\u0432\u0430\u0440\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0448\u0435\u0439 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043f\u043e\u0434 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c root \u0431\u0435\u0437 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u0430\u0440\u043e\u043b\u044f, \u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 telnetd \u0438\u0437 \u043d\u0430\u0431\u043e\u0440\u0430 GNU InetUtils \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0435\u0440\u0438\u044f \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 telnetd, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u043a\u043e\u043d\u0446\u0435 \u044f\u043d\u0432\u0430\u0440\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0448\u0435\u0439 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043f\u043e\u0434 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c root \u0431\u0435\u0437 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u0430\u0440\u043e\u043b\u044f, \u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 telnetd \u0438\u0437 \u043d\u0430\u0431\u043e\u0440\u0430 GNU InetUtils \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-02-25T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-25T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Una serie de nuevas vulnerabilidades en telnetd que permiten obtener privilegios root en el sistema | ProHoster","description":"Tras la vulnerabilidad identificada a finales de enero que permit\u00eda conectarse como usuario root sin verificar la contrase\u00f1a, se han descubierto varios m\u00e9todos para elevar privilegios en el servidor telnetd del conjunto GNU InetUtils.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0435\u0440\u0438\u044f \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 telnetd, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u043a\u043e\u043d\u0446\u0435 \u044f\u043d\u0432\u0430\u0440\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0448\u0435\u0439 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043f\u043e\u0434 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c root \u0431\u0435\u0437 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u0430\u0440\u043e\u043b\u044f, \u0432 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 telnetd \u0438\u0437 \u043d\u0430\u0431\u043e\u0440\u0430 GNU InetUtils \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/seriya-novyh-uyazvimostej-v-telnetd-pozvolyayushhih-poluchit-root-privilegii-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-02-25T15:11:54+00:00","article:modified_time":"2026-02-25T15:11:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"162791","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-25 15:12:53","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-25 15:11:55","updated":"2026-02-25 15:12:53","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/162791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=162791"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/162791\/revisions"}],"predecessor-version":[{"id":165657,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/162791\/revisions\/165657"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=162791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=162791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=162791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}