Kyu Neushwaistein discovered that telnetd from inetutils does not sanitize the USER environment variable before passing it on to login. A remote attacker can take advantage of this flaw to login as root, bypassing normal authentication processes.
https://security-tracker.debian.org/tracker/DSA-6106-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6106-1
Continue reading...

