Subject: bin/31344: rexecd obsolete
To: None <gnats-admin@netbsd.org, netbsd-bugs@netbsd.org>
From: None <zafer@gmx.org>
List: netbsd-bugs
Date: 09/18/2005 22:50:00
>Number:         31344
>Category:       bin
>Synopsis:       rexecd obsolete
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    bin-bug-people
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Sun Sep 18 22:50:00 +0000 2005
>Originator:     Zafer Aydogan
>Release:        3.99.9
>Organization:
>Environment:
i386
>Description:
I suggest to remove rexecd from inetd.conf 

the rexecd in /etc/inetd.conf  is server that implements a particularly insecure method of executing commands remotely.
There are no rexec clients in the NetBSD tree, and the client function rexec(3) is present only in libcompat. It has been documented as "obsolete" since 4.3BSD, and its use has been discouraged in the man page for over 10 years.

>How-To-Repeat:

>Fix: