Bug#4190: moderate security hole in telnetd

1996-08-19 Thread Miquel van Smoorenburg
You (Bernd Eckenfels) wrote: > > A quick workaround is to change envarok() in telnetd/state.c as > > appended. My guess is that only telnetd needs to be changed for now, > > as neither rlogin nor rsh (if I remember correctly) allow the client > > to pass in environment variables. > > Is this envi

Bug#4190: moderate security hole in telnetd

1996-08-19 Thread Bernd Eckenfels
> A quick workaround is to change envarok() in telnetd/state.c as > appended. My guess is that only telnetd needs to be changed for now, > as neither rlogin nor rsh (if I remember correctly) allow the client > to pass in environment variables. Is this environment variable sourced for SUID/SGID pr

Bug#4190: moderate security hole in telnetd

1996-08-19 Thread Klee Dienes
Package: netstd Version: 2.06-1 A bug currently making the rounds on the bugtraq mailing list: The resolver library appears to allow the environment variable RESOLV_HOST_CONF to be used to specify a pathname for an alternate host.conf. It also has the unfortunate behavior of printing the text o