[4669] in Athena Bugs

home help back first fref pref prev next nref lref last post

vax 6.4R: /etc/ftpd

daemon@ATHENA.MIT.EDU (John T Kohl)
Mon Apr 2 09:41:19 1990

Date: Mon, 2 Apr 90 09:41:05 -0400
From: John T Kohl <jtkohl@ATHENA.MIT.EDU>
To: bugs@ATHENA.MIT.EDU
System name:		lycus
Type and version:	CVAXSTAR 6.4R
Display type:		SM

What were you trying to do?
	Verify that the Athena sources for FTPD have the most recent
changes from Berkeley to avoid Morris' & other security holes.

What's wrong:
	Athena doesn't have the most recent ftpd sources.  Here's what I
have (which I got from Berkeley a while ago) (output of a 'what' command
on *.[chy] in the ftpd sources):

ftpcmd.c
        ftpcmd.y        5.13 (Berkeley) 11/30/88
        yaccpar 4.1     (Berkeley)      2/11/83
ftpcmd.y
        ftpcmd.y        5.13 (Berkeley) 11/30/88
        ftpcmd.y        5.13 (Berkeley) 11/30/88
ftpd.c
         Copyright (c) 1985 Regents of the University of California.\n\
        ftpd.c  5.19 (Berkeley) 11/30/88 + portability hacks by rick@seismo.css.gov
getusershell.c
        getusershell.c  5.5 (Berkeley) 7/21/88
glob.c
        glob.c  5.6 (Berkeley) 11/30/88
logwtmp.c
        logwtmp.c       5.2 (Berkeley) 9/20/88
        logwtmp.c       5.2 (Berkeley) 9/22/88
popen.c
        popen.c 5.7 (Berkeley) 9/1/88
        popen.c 5.3 (Berkeley) 11/30/88
strpbrk.c
        strpbrk.c       5.5 (Berkeley) 7/14/88 + portability hacks by rick@seismo.css.gov
strtok.c
        strtok.c        5.5 (Berkeley) 8/1/88
vers.c

	please note that arc.ames.nasa.gov and bitsy have older versions
of ftpd up for ftp.  ns.uu.net might have a newer version, but it
doesn't allow FTP during east-coast business hours.

What should have happened:
	Athena should get the most recent, bug free versions.
	

	THIS IS A SECURITY CRITICAL CHANGE.

Please describe any relevant documentation references:
	lycus:/site/ftpd/README	

home help back first fref pref prev next nref lref last post