111 points by paimapi 4 days ago | 46 comments | View on ycombinator
collinfunk 3 days ago |
ErroneousBosh 3 days ago |
> That was so long ago that RISC was still a distant dream.
Yeah ARM would like to have a word with you. I'd been using RISC on the desktop for about five years by then and I was not an early adopter.
e12e 3 days ago |
https://www.cve.org/CVERecord?id=CVE-2007-0882
Might be a 32 year old bug, but it's practically also a 19 years old exploit?
Ed: I'm confusing TFA with
https://nvd.nist.gov/vuln/detail/cve-2026-24061
Which seems pretty much identical with the 2007 cve.
b800h 3 days ago |
Ahem
krautsauer 3 days ago |
JdeBP 2 days ago |
Except for: There is no bug that originates in a GNU version of an old networking program and magically makes its way into the NetBSD, FreeBSD, DragonFlyBSD, and OpenBSD (Yes; I checked.) versions of that program.
History simply didn't happen that way.
This bug goes as far back at least as far as the Jolitz-released 386BSD source for libexec/telnetd , where it can be found and which is credited in the GNU versions of the file. GNU just took the 386BSD code. But BSD had a telnetd before 386BSD. In BSD, telnetd itself goes back to 1983. Although its code to do line mode did not pre-date RFC 1116, which was published in August 1989.
The code to do line mode was written the month after that RFC, by Paul Borman, and the bug is in the very first version of that code:
* https://github.com/dspinellis/unix-history-repo/blob/dc8d504...
This bug is not 32 years old.
notimetorelax 3 days ago |
Rooster61 3 days ago |
The bug, being a bug, proceeds to overflow the buffer
sjpb 3 days ago |
johnnyApplePRNG 3 days ago |
Or is there a tradeoff?
Fewer ancient holes like this for their hackers but wide open access to anyone who installs codex or claude code?
mitxela 3 days ago |
undefined 3 days ago |
jeffbee 3 days ago |
khrbtxyz 3 days ago |
mzs 3 days ago |
undefined 3 days ago |
egorfine 3 days ago |
/s
Perhaps I am just unlucky in my interactions, but I feel like this entitlement is too common among software security people. Note that I see zero return in spending time working on Inetutils, and I find other projects I work on more interesting.
[1] https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [2] https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [3] https://www.openwall.com/lists/oss-security/2026/03/12/4