Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1221462 > unrolled thread

Bug#1088190: util-linux: Please restore mesg, write

Started byBen Wong <bugs.debian.org@wongs.net>
First post2024-11-24 21:10 +0100
Last post2024-12-08 21:00 +0100
Articles 4 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1088190: util-linux: Please restore mesg, write Ben Wong <bugs.debian.org@wongs.net> - 2024-11-24 21:10 +0100
    Bug#1088190: util-linux: Please restore mesg, write Chris Hofstaedtler <zeha@debian.org> - 2024-11-25 02:20 +0100
      Bug#1088190: util-linux: Please restore mesg, write Ben Wong <ben@wongs.net> - 2024-11-25 07:00 +0100
        Bug#1088190: util-linux: Please restore mesg, write Chris Hofstaedtler <zeha@debian.org> - 2024-12-08 21:00 +0100

#1221462 — Bug#1088190: util-linux: Please restore mesg, write

FromBen Wong <bugs.debian.org@wongs.net>
Date2024-11-24 21:10 +0100
SubjectBug#1088190: util-linux: Please restore mesg, write
Message-ID<JMr5D-bjjG-3@gated-at.bofh.it>
Package: util-linux
Version: 2.40.2-11
Severity: normal
X-Debbugs-Cc: bugs.debian.org@wongs.net

Dear Maintainer,

I read that mesg and write were removed recently because "people use
more secure methods of chatting nowadays." I am guessing this is
related to the recent security problem where Debian defaulted to 'mesg
n' and 'write' was not filtering Esc. Simply removing the programs may
seem like a fix, but unfortunately it is not so easy.

These are POSIX.2 shell tools which work universally and it would be a
shame if Debian were to be the incompatible UNIX.

Thanks,

--Ben





-- System Information:
Debian Release: trixie/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.11.9-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages util-linux depends on:
ii  libblkid1       2.40.2-11
ii  libc6           2.40-3
ii  libcap-ng0      0.8.5-3+b1
ii  libcrypt1       1:4.4.36-5
ii  libmount1       2.40.2-11
ii  libpam-modules  1.5.3-7+b1
ii  libpam-runtime  1.5.3-7
ii  libpam0g        1.5.3-7+b1
ii  libselinux1     3.7-3+b1
ii  libsmartcols1   2.40.2-11
ii  libsystemd0     257~rc2-3
ii  libtinfo6       6.5-2+b1
ii  libudev1        257~rc2-3
ii  libuuid1        2.40.2-11

Versions of packages util-linux recommends:
ii  sensible-utils  0.0.24

Versions of packages util-linux suggests:
ii  dosfstools          4.2-1.1
ii  kbd                 2.6.4-3
ii  util-linux-extra    2.40.2-11
ii  util-linux-locales  2.40.2-11
pn  wtmpdb              <none>

-- no debconf information

[toc] | [next] | [standalone]


#1221495

FromChris Hofstaedtler <zeha@debian.org>
Date2024-11-25 02:20 +0100
Message-ID<JMvVE-bmfr-9@gated-at.bofh.it>
In reply to#1221462
Control: tags -1 = wontfix

On Sun, Nov 24, 2024 at 12:02:02PM -0800, Ben Wong wrote:
> I read that mesg and write were removed recently because "people use
> more secure methods of chatting nowadays." I am guessing this is
> related to the recent security problem where Debian defaulted to 'mesg
> n' and 'write' was not filtering Esc. Simply removing the programs may
> seem like a fix, but unfortunately it is not so easy.

Removing them is from my POV the right way to go. I somewhat expect
other mainline distros to do the same, sooner or later.

> These are POSIX.2 shell tools which work universally and it would be a
> shame if Debian were to be the incompatible UNIX.

POSIX could/should change, I guess.

Chris

[toc] | [prev] | [next] | [standalone]


#1221505

FromBen Wong <ben@wongs.net>
Date2024-11-25 07:00 +0100
Message-ID<JMAiB-boSx-1@gated-at.bofh.it>
In reply to#1221495

[Multipart message — attachments visible in raw view] — view raw

Thanks.

I apologize but I couldn't find where on the mailing list this was discussed so I need a little more info to proceed.

* I suspect this is unlikely, but is the "WONTFIX" just for until-linux, so it would be possible for Debian to ship these tools in a different package? 

* Or, is the thinking that none of the Debian volunteers is willing to keep such crufty code audited and as such the programs are essentially orphaned? 

* Is there some known or suspected attack vector other than through sending Esc? If so, it would be good for admins to know to be able to weigh the risks of manually installing the programs from source.

* What is Debian's suggestion now for communicating with users who are ssh'ed into a system?

Thank you for your time,

--Ben



On November 24, 2024 5:12:39 PM PST, Chris Hofstaedtler <zeha@debian.org> wrote:
>Control: tags -1 = wontfix
>
>On Sun, Nov 24, 2024 at 12:02:02PM -0800, Ben Wong wrote:
>> I read that mesg and write were removed recently because "people use
>> more secure methods of chatting nowadays." I am guessing this is
>> related to the recent security problem where Debian defaulted to 'mesg
>> n' and 'write' was not filtering Esc. Simply removing the programs may
>> seem like a fix, but unfortunately it is not so easy.
>
>Removing them is from my POV the right way to go. I somewhat expect
>other mainline distros to do the same, sooner or later.
>
>> These are POSIX.2 shell tools which work universally and it would be a
>> shame if Debian were to be the incompatible UNIX.
>
>POSIX could/should change, I guess.
>
>Chris
>

[toc] | [prev] | [next] | [standalone]


#1223259

FromChris Hofstaedtler <zeha@debian.org>
Date2024-12-08 21:00 +0100
Message-ID<JRvBD-eWFY-5@gated-at.bofh.it>
In reply to#1221505
* Ben Wong <ben@wongs.net> [241125 06:47]:
> I apologize but I couldn't find where on the mailing list this was discussed so I need a little more info to proceed.

As there was security context, the discussion was not on a public
mailing list, unfortunately.

> * Is there some known or suspected attack vector other than through sending Esc? If so, it would be good for admins to know to be able to weigh the risks of manually installing the programs from source.

The discussion on oss-security back then yielded that there is no
safe way of writing to another user's terminal.

> * What is Debian's suggestion now for communicating with users who are ssh'ed into a system?

Personally, I would talk to them, or send them a text.

Chris

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web