Date: Wed, 12 Apr 1995 12:50:05 +0400 From: "Andrey A. Chernov, Black Mage" <ache@astral.msk.su> To: Paul Traina <pst@shockwave.com> Cc: CVS-commiters@freefall.cdrom.com, cvs-libexec@freefall.cdrom.com Subject: Re: cvs commit: src/libexec/atrun atrun.man Makefile atrun.c atrun.8 atrun.h Message-ID: <iIzGvYlWW2@astral.msk.su> In-Reply-To: <199504120314.UAA02122@precipice.shockwave.com>; from Paul Traina at Tue, 11 Apr 1995 20:14:38 -0700 References: <199504120314.UAA02122@precipice.shockwave.com>
next in thread | previous in thread | raw e-mail | index | archive | help
In message <199504120314.UAA02122@precipice.shockwave.com> Paul Traina writes: >Did you just upgrade to 2.7a? 2.7a does not actually fix the security hole, >at least according to my examination of the distribution source code. Yes, with my own more stronger checking (followed to author). Original 2.7a still have hole on FreeBSD because setreuid() don't change real uid. >Also, I was a little concerned to see pathnames.h et al go away. Has this >program suddently gotten much less bsd-like in nature? Less BSD-like, but more compatible with original version and its future releases, it makes upgrade process more easy. Really, Makefile.inc replace pathnames.h with defines for original version. -- Andrey A. Chernov : And I rest so composedly, /Now, in my bed, ache@astral.msk.su : That any beholder /Might fancy me dead - FidoNet: 2:5020/230.3 : Might start at beholding me, /Thinking me dead. RELCOM Team,FreeBSD Team : E.A.Poe From "For Annie" 1849
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?iIzGvYlWW2>