From owner-freebsd-bugs@FreeBSD.ORG Wed Feb 15 14:10:07 2006 Return-Path: X-Original-To: freebsd-bugs@hub.freebsd.org Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 475E216A420 for ; Wed, 15 Feb 2006 14:10:07 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 147D943D49 for ; Wed, 15 Feb 2006 14:10:06 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1FEA5aA031540 for ; Wed, 15 Feb 2006 14:10:05 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1FEA5G6031539; Wed, 15 Feb 2006 14:10:05 GMT (envelope-from gnats) Resent-Date: Wed, 15 Feb 2006 14:10:05 GMT Resent-Message-Id: <200602151410.k1FEA5G6031539@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Juraj Lutter Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8C7A716A420 for ; Wed, 15 Feb 2006 14:05:18 +0000 (GMT) (envelope-from otis@remedy.wilbury.sk) Received: from remedy.wilbury.sk (remedy.wilbury.sk [217.73.27.10]) by mx1.FreeBSD.org (Postfix) with SMTP id A46EA43D8C for ; Wed, 15 Feb 2006 14:05:17 +0000 (GMT) (envelope-from otis@remedy.wilbury.sk) Received: (qmail 65020 invoked by uid 1000); 15 Feb 2006 14:05:15 -0000 Message-Id: <20060215140515.65019.qmail@remedy.wilbury.sk> Date: 15 Feb 2006 14:05:15 -0000 From: Juraj Lutter To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: uhlar@nextra.sk Subject: bin/93391: inetd's internal auth service allows use of ~/.fakeid X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Juraj Lutter List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Feb 2006 14:10:07 -0000 >Number: 93391 >Category: bin >Synopsis: inetd's internal auth service allows use of ~/.fakeid >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Wed Feb 15 14:10:04 GMT 2006 >Closed-Date: >Last-Modified: >Originator: Juraj Lutter >Release: FreeBSD 5.4-STABLE i386 >Organization: >Environment: System: FreeBSD remedy.wilbury.sk 5.4-STABLE FreeBSD 5.4-STABLE #0: Sun Jul 17 13:16:48 CEST 2005 root@remedy.wilbury.sk:/usr/obj/usr/src/sys/remedy i386 >Description: default settings of inetd allows users to use ~/.fakeid file to change IDENT server replies. >How-To-Repeat: use "-r" flag (as in default inetd config) to "auth" internal service >Fix: remove "-r" and probably "-n", too from default inetd.conf >Release-Note: >Audit-Trail: >Unformatted: