Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 30 Aug 1995 14:02:44 -0400 (EDT)
From:      "Jonathan M. Bresler" <jmb@kryten.Atinc.COM>
To:        Christoph Kukulies <kuku@gilberto.physik.rwth-aachen.de>
Cc:        freebsd-hackers@freefall.FreeBSD.org
Subject:   Re: *READ THIS* snapshot fixes security hole *READ THIS* (fwd)
Message-ID:  <Pine.3.89.9508301316.G14671-0100000@kryten.atinc.com>
In-Reply-To: <199508301035.MAA16690@gilberto.physik.rwth-aachen.de>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 30 Aug 1995, Christoph Kukulies wrote:

> I don't know if this concerns FreeBSD too but just FYI I'm
> forwarding this from the NetBSD list:
> 
> > Here are the files in /bin and /sbin which call syslog()

based upon a recursive "grep -l 'syslog('"
here is the list for -stable as of last night.

/usr/src/bin/date/date.c
/usr/src/gnu/libexec/ypxfr/log.c
/usr/src/gnu/usr.bin/perl/lib/syslog.pl
/usr/src/gnu/usr.sbin/yppasswdd/pw_copy.c
/usr/src/gnu/usr.sbin/yppasswdd/pw_util.c
/usr/src/gnu/usr.sbin/yppasswdd/update.c
/usr/src/gnu/usr.sbin/ypserv/server.c
/usr/src/lib/libc/gen/getpwent.c
/usr/src/lib/libc/gen/syslog.3
/usr/src/lib/libc/gen/syslog.c
/usr/src/lib/libc/net/gethostbydns.c
/usr/src/lib/libcom_err/doc/com_err.texinfo
/usr/src/lib/libskey/skeyaccess.c
/usr/src/libexec/atrun/atrun.c
/usr/src/libexec/bootpd/Announce
/usr/src/libexec/bootpd/Changes
/usr/src/libexec/bootpd/README
/usr/src/libexec/bootpd/report.c
/usr/src/libexec/comsat/comsat.c
/usr/src/libexec/fingerd/fingerd.c
/usr/src/libexec/ftpd/ftpcmd.y
/usr/src/libexec/ftpd/ftpd.c
/usr/src/libexec/getty/main.c
/usr/src/libexec/mail.local/mail.local.c
/usr/src/libexec/rbootd/bpf.c
/usr/src/libexec/rbootd/parseconf.c
/usr/src/libexec/rbootd/rbootd.c
/usr/src/libexec/rbootd/rmpproto.c
/usr/src/libexec/rbootd/utils.c
/usr/src/libexec/rexecd/rexecd.c
/usr/src/libexec/rlogind/rlogind.c
/usr/src/libexec/rpc.rstatd/rstat_proc.c
/usr/src/libexec/rpc.rstatd/rstatd.c
/usr/src/libexec/rpc.rusersd/rusers_proc.c
/usr/src/libexec/rpc.rusersd/rusersd.c
/usr/src/libexec/rshd/rshd.c
/usr/src/libexec/talkd/print.c
/usr/src/libexec/talkd/process.c
/usr/src/libexec/talkd/table.c
/usr/src/libexec/talkd/talkd.c
/usr/src/libexec/telnetd/state.c
/usr/src/libexec/telnetd/sys_term.c
/usr/src/libexec/telnetd/telnetd.c
/usr/src/libexec/telnetd/utility.c
/usr/src/libexec/tftpd/tftpd.c
/usr/src/libexec/uucpd/uucpd.c
/usr/src/sbin/adjkerntz/adjkerntz.c
/usr/src/sbin/init/init.c
/usr/src/sbin/mount_nfs/mount_nfs.c
/usr/src/sbin/mount_portal/activate.c
/usr/src/sbin/mount_portal/conf.c
/usr/src/sbin/mount_portal/mount_portal.c
/usr/src/sbin/mount_portal/pt_file.c
/usr/src/sbin/mount_portal/pt_tcp.c
/usr/src/sbin/mountd/mountd.c
/usr/src/sbin/newfs/newfs.c
/usr/src/sbin/nfsd/nfsd.c
/usr/src/sbin/nfsiod/nfsiod.c
/usr/src/sbin/rdisc/rdisc.c
/usr/src/sbin/reboot/reboot.c
/usr/src/sbin/savecore/savecore.c
/usr/src/sbin/shutdown/shutdown.c
/usr/src/sbin/slattach/slattach.c
/usr/src/sbin/startslip/startslip.c
/usr/src/secure/libexec/telnetd/state.c
/usr/src/secure/libexec/telnetd/sys_term.c
/usr/src/secure/libexec/telnetd/telnetd.c
/usr/src/secure/libexec/telnetd/utility.c
/usr/src/share/doc/psd/21.ipc/4.t
/usr/src/share/doc/psd/21.ipc/5.t
/usr/src/share/man/man0/title.urm
/usr/src/sys/i386/linux/linux_dummy.c
/usr/src/sys/i386/linux/linux_sysent.c
/usr/src/sys/sys/syslog.h
/usr/src/usr.bin/chat/chat.c
/usr/src/usr.bin/logger/logger.c
/usr/src/usr.bin/login/klogin.c
/usr/src/usr.bin/login/login.c
/usr/src/usr.bin/login/login_access.c
/usr/src/usr.bin/login/login_fbtab.c
/usr/src/usr.bin/ncftp/ftp.c
/usr/src/usr.bin/ncftp/patchlevel.h
/usr/src/usr.bin/su/su.c
/usr/src/usr.bin/vacation/vacation.c
/usr/src/usr.bin/yacc/test/ftp.tab.c
/usr/src/usr.bin/yacc/test/ftp.y
/usr/src/usr.sbin/XNSrouted/main.c
/usr/src/usr.sbin/XNSrouted/startup.c
/usr/src/usr.sbin/XNSrouted/tables.c
/usr/src/usr.sbin/XNSrouted/trace.c
/usr/src/usr.sbin/amd/amd/ChangeLog
/usr/src/usr.sbin/amd/amd/xutil.c
/usr/src/usr.sbin/amd/config/os-defaults.h
/usr/src/usr.sbin/amd/config/os-hpux.h
/usr/src/usr.sbin/amd/config/os-irix.h
/usr/src/usr.sbin/amd/config/os-irix3.h
/usr/src/usr.sbin/amd/config/os-irix4.h
/usr/src/usr.sbin/amd/config/os-u2_2.h
/usr/src/usr.sbin/amd/config/os-u3_0.h
/usr/src/usr.sbin/amd/config/os-u4_0.h
/usr/src/usr.sbin/amd/config/os-u4_2.h
/usr/src/usr.sbin/bootparamd/bootparamd/bootparamd.c
/usr/src/usr.sbin/cron/cron/config.h
/usr/src/usr.sbin/cron/lib/misc.c
/usr/src/usr.sbin/inetd/inetd.c
/usr/src/usr.sbin/lpr/lpd/lpd.c
/usr/src/usr.sbin/lpr/lpd/printjob.c
/usr/src/usr.sbin/lpr/lpd/recvjob.c
/usr/src/usr.sbin/mrouted/main.c
/usr/src/usr.sbin/named/db_dump.c
/usr/src/usr.sbin/named/db_glue.c
/usr/src/usr.sbin/named/db_load.c
/usr/src/usr.sbin/named/db_reload.c
/usr/src/usr.sbin/named/db_save.c
/usr/src/usr.sbin/named/db_secure.c
/usr/src/usr.sbin/named/db_update.c
/usr/src/usr.sbin/named/named.8
/usr/src/usr.sbin/named/ns_forw.c
/usr/src/usr.sbin/named/ns_init.c
/usr/src/usr.sbin/named/ns_main.c
/usr/src/usr.sbin/named/ns_maint.c
/usr/src/usr.sbin/named/ns_req.c
/usr/src/usr.sbin/named/ns_resp.c
/usr/src/usr.sbin/named/ns_stats.c
/usr/src/usr.sbin/named/ns_validate.c
/usr/src/usr.sbin/named/portability.h
/usr/src/usr.sbin/named/storage.c
/usr/src/usr.sbin/named/xfer/named-xfer.c
/usr/src/usr.sbin/portmap/from_local.c
/usr/src/usr.sbin/portmap/pmap_check.c
/usr/src/usr.sbin/portmap/portmap.c
/usr/src/usr.sbin/pppd/auth.c
/usr/src/usr.sbin/pppd/chap.c
/usr/src/usr.sbin/pppd/fsm.c
/usr/src/usr.sbin/pppd/ipcp.c
/usr/src/usr.sbin/pppd/lcp.c
/usr/src/usr.sbin/pppd/lock.c
/usr/src/usr.sbin/pppd/main.c
/usr/src/usr.sbin/pppd/options.c
/usr/src/usr.sbin/pppd/pppd.h
/usr/src/usr.sbin/pppd/sys-bsd.c
/usr/src/usr.sbin/pppd/upap.c
/usr/src/usr.sbin/rarpd/arptab.c
/usr/src/usr.sbin/rarpd/rarpd.8
/usr/src/usr.sbin/rarpd/rarpd.c
/usr/src/usr.sbin/routed/input.c
/usr/src/usr.sbin/routed/main.c
/usr/src/usr.sbin/routed/startup.c
/usr/src/usr.sbin/routed/tables.c
/usr/src/usr.sbin/rwhod/rwhod.c
/usr/src/usr.sbin/sendmail/RELEASE_NOTES
/usr/src/usr.sbin/sendmail/contrib/rcpt-streaming
/usr/src/usr.sbin/sendmail/src/READ_ME
/usr/src/usr.sbin/sendmail/src/alias.c
/usr/src/usr.sbin/sendmail/src/collect.c
/usr/src/usr.sbin/sendmail/src/conf.c
/usr/src/usr.sbin/sendmail/src/conf.h
/usr/src/usr.sbin/sendmail/src/daemon.c
/usr/src/usr.sbin/sendmail/src/deliver.c
/usr/src/usr.sbin/sendmail/src/envelope.c
/usr/src/usr.sbin/sendmail/src/err.c
/usr/src/usr.sbin/sendmail/src/headers.c
/usr/src/usr.sbin/sendmail/src/main.c
/usr/src/usr.sbin/sendmail/src/mci.c
/usr/src/usr.sbin/sendmail/src/queue.c
/usr/src/usr.sbin/sendmail/src/readcf.c
/usr/src/usr.sbin/sendmail/src/recipient.c
/usr/src/usr.sbin/sendmail/src/savemail.c
/usr/src/usr.sbin/sendmail/src/srvrsmtp.c
/usr/src/usr.sbin/sendmail/src/udb.c
/usr/src/usr.sbin/sendmail/src/usersmtp.c
/usr/src/usr.sbin/sendmail/src/util.c
/usr/src/usr.sbin/sliplogin/sliplogin.c
/usr/src/usr.sbin/syslogd/syslogd.c
/usr/src/usr.sbin/timed/timed/candidate.c
/usr/src/usr.sbin/timed/timed/correct.c
/usr/src/usr.sbin/timed/timed/globals.h
/usr/src/usr.sbin/timed/timed/master.c
/usr/src/usr.sbin/timed/timed/measure.c
/usr/src/usr.sbin/timed/timed/readmsg.c
/usr/src/usr.sbin/timed/timed/slave.c
/usr/src/usr.sbin/timed/timed/timed.c
/usr/src/usr.sbin/xntpd/doc/acts.c
/usr/src/usr.sbin/xntpd/lib/authreadkeys.c
/usr/src/usr.sbin/xntpd/lib/emalloc.c
/usr/src/usr.sbin/xntpd/lib/msyslog.c
/usr/src/usr.sbin/xntpd/lib/systime.c
/usr/src/usr.sbin/xntpd/ntpdate/ntpdate.c
/usr/src/usr.sbin/xntpd/ntptrace/ntptrace.c
/usr/src/usr.sbin/xntpd/parse/clk_rawdcf.c
/usr/src/usr.sbin/xntpd/parse/clk_trimtsip.c
/usr/src/usr.sbin/xntpd/parse/parse.c
/usr/src/usr.sbin/xntpd/parse/util/dcfd.c
/usr/src/usr.sbin/xntpd/util/README
/usr/src/usr.sbin/xntpd/xntpd/ntp_config.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_control.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_filegen.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_intres.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_io.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_leap.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_loopfilter.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_peer.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_proto.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_refclock.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_unixclock.c
/usr/src/usr.sbin/xntpd/xntpd/ntp_util.c
/usr/src/usr.sbin/xntpd/xntpd/ntpd.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_acts.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_chu.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_datum.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_gpstm.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_irig.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_leitch.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_msfees.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_mx4200.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_omega.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_parse.c
/usr/src/usr.sbin/xntpd/xntpd/refclock_tpro.c
/usr/src/usr.sbin/ypbind/ypbind.8
/usr/src/usr.sbin/ypbind/ypbind.c


Jonathan M. Bresler  jmb@kryten.atinc.com       | Analysis & Technology, Inc.  
FreeBSD Postmaster   jmb@FreeBSD.Org            | 2341 Jeff Davis Hwy
play go.                                        | Arlington, VA 22202
ride bike. hack FreeBSD.--ah the good life      | 703-418-2800 x346




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.3.89.9508301316.G14671-0100000>