|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: [sa2c
and.or.jp: bin/21704: enabling fingerd makes files world readable]From: Warner Losh (imp
VILLAGE.ORG)Date: Wed Oct 04 2000 - 12:36:40 CDT
- Next message: Nick FitzGerald: "Re: Pegasus mail file reading vulnerability"
- Previous message: Adrian Chadd: "Re: BSD chpass"
- In reply to: Przemyslaw Frasunek: "Re: [sa2c
and.or.jp: bin/21704: enabling fingerd makes files world readable]"
- Reply: Warner Losh: "Re: [sa2c
and.or.jp: bin/21704: enabling fingerd makes files world readable]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
In message <20001003201812.K6009
riget.scene.pl> Przemyslaw Frasunek writes:
: BTW. Problem persists only in 4.x branch. Of course, it allows also
: to traverse directory structures:
The problem was fixed in the 4.x branch:
revision 1.15.2.4
date: 2000/10/02 22:28:46; author: brian; state: Exp; lines: +11 -1
MFC: Don't allow finger /somefile, only allow filname expansions from
inside /etc/finger.conf
Warner
- Next message: Nick FitzGerald: "Re: Pegasus mail file reading vulnerability"
- Previous message: Adrian Chadd: "Re: BSD chpass"
- In reply to: Przemyslaw Frasunek: "Re: [sa2c
and.or.jp: bin/21704: enabling fingerd makes files world readable]"
- Reply: Warner Losh: "Re: [sa2c
and.or.jp: bin/21704: enabling fingerd makes files world readable]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]