Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 05 Jul 2000 22:58:20 -0400
From:      "Louis A. Mamakos" <louie@TransSys.COM>
To:        Kris Kennaway <kris@FreeBSD.ORG>
Cc:        "Jordan K. Hubbard" <jkh@zippy.osd.bsdi.com>, Jean-Marc Zucconi <jmz@FreeBSD.ORG>, Alfred Perlstein <bright@wintelcom.net>, cvs-committers@FreeBSD.ORG, cvs-all@FreeBSD.ORG
Subject:   Re: cvs commit: ports/x11/XFree86-4 Makefile 
Message-ID:  <200007060258.WAA21955@whizzo.transsys.com>
In-Reply-To: Your message of "Wed, 05 Jul 2000 13:46:25 PDT." <Pine.BSF.4.21.0007051345220.36226-100000@freefall.freebsd.org> 
References:  <Pine.BSF.4.21.0007051345220.36226-100000@freefall.freebsd.org> 

next in thread | previous in thread | raw e-mail | index | archive | help
> On Wed, 5 Jul 2000, Jordan K. Hubbard wrote:
> 
> > > They have fixed the _known_ holes but the server is still setuid
> > > root so the possibility of undiscovered security bugs remains.
> > 
> > Which is all that can be said for *any* setuid root binary in FreeBSD. :-)
> 
> We don't have any setuid root binaries which are this complex and fearsome
> :-)

Uh,

-r-sr-xr-x  1 root  wheel  316348 Jun  5 22:16 /usr/libexec/sendmail/sendmail*

I'm not sure if I fear X or sendmail more, but it's pretty close!

louie


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200007060258.WAA21955>