[143] in linux-security and linux-alert archive
in.talkd+flash
daemon@ATHENA.MIT.EDU (Alan Cox)
Mon Mar 13 09:59:11 1995
From: iialan@iifeak.swan.ac.uk (Alan Cox)
To: linux-security@tarsier.cv.nrao.edu
Date: Mon, 13 Mar 1995 12:15:49 +0000 (GMT)
Reply-To: linux-security@tarsier.cv.nrao.edu
The sunsite in.talkd with flash protection has a critical error that
allows arbitary commands to be executed on a machine running it. (It uses
system to mail complaints and doesnt check for things like ';' in the
hostname).
Everyone should fix it or remove it ASAP