summaryrefslogtreecommitdiffstats
path: root/gnu/usr.bin/cpio
diff options
context:
space:
mode:
authorjdp <jdp@FreeBSD.org>1997-02-08 20:54:38 +0000
committerjdp <jdp@FreeBSD.org>1997-02-08 20:54:38 +0000
commitc54bd2595235d8db3263818e3e4e58b963c69ac0 (patch)
tree14b156151bbd804b683a48be5865d5d6dd43181b /gnu/usr.bin/cpio
parent9e4d6045b80be63aceb0caeadedaf9256db0988a (diff)
downloadFreeBSD-src-c54bd2595235d8db3263818e3e4e58b963c69ac0.zip
FreeBSD-src-c54bd2595235d8db3263818e3e4e58b963c69ac0.tar.gz
Security fix. Strip the encrypted passwords out of the "master.passwd"
diff output, and replace them with "(password)". The diffs get mailed to root, which in many cases is forwarded across the Internet. A patient sniffer could acquire the entire "master.passwd" file by saving all the diffs. With this fix, you still see that the password changed, but you don't see the details. Unless somebody talks me out of it, I am going to merge this into -2.2 in 48 hours.
Diffstat (limited to 'gnu/usr.bin/cpio')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud