From owner-freebsd-commit Thu Jul 20 05:35:07 1995 Return-Path: commit-owner Received: (from majordom@localhost) by freefall.cdrom.com (8.6.11/8.6.6) id FAA06743 for commit-outgoing; Thu, 20 Jul 1995 05:35:07 -0700 Received: (from majordom@localhost) by freefall.cdrom.com (8.6.11/8.6.6) id FAA06729 for cvs-user-outgoing; Thu, 20 Jul 1995 05:35:05 -0700 Received: (from pst@localhost) by freefall.cdrom.com (8.6.11/8.6.6) id FAA06719 ; Thu, 20 Jul 1995 05:35:03 -0700 Date: Thu, 20 Jul 1995 05:35:03 -0700 From: Paul Traina Message-Id: <199507201235.FAA06719@freefall.cdrom.com> To: CVS-commiters, cvs-user Subject: cvs commit: src/secure/libexec/telnetd sys_term.c Sender: commit-owner@FreeBSD.org Precedence: bulk pst 95/07/20 05:35:02 Modified: secure/libexec/telnetd sys_term.c Log: When hostname len > 8, name replaced with dot notation when -u flag not specified (default case). Use _PATH_* for utmp/wtmp. Support for >32 PTYs. >Submitted by: Heikki Suonsivu Plug already known security hole. (Brought over from 1.1.5): Fixed security problem with telnetd, which allowed telnet -l -hcert.org localhost to change the user's host in utmp. Thanks to Matthew Green for showing me this one. >Reviewed by: karl, guido >Submitted by: mrgreen@mame.mu.oz.au Obtained from: FreeBSD insecure telnetd