Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Mar 95 15:08:27 MST
From:      terry@cs.weber.edu (Terry Lambert)
To:        Remy.Card@masi.ibp.fr (Remy CARD)
Cc:        hackers@FreeBSD.org
Subject:   Re: finger @ bug (fwd)
Message-ID:  <9503132208.AA04366@cs.weber.edu>
In-Reply-To: <199503131944.UAA10022@hebe.ibp.fr> from "Remy CARD" at Mar 13, 95 08:44:27 pm

next in thread | previous in thread | raw e-mail | index | archive | help
> 	This has just been sent to the linux-security mailing list.  Since
> the FreeBSD's fingerd also has the bug, could someone please integrate the
> fix?

[ ... finger user@host.other.domain@host.domain ... ]

Why is this a problem?

I've used this for forever.  It's lets a firewall machine accept
finger requests for forwarding without opening machines in the domain
to fingerd buffer overrun attacks.


					Terry Lambert
					terry@cs.weber.edu
---
Any opinions in this posting are my own and not those of my present
or previous employers.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?9503132208.AA04366>