Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 12 Apr 1995 12:50:05 +0400
From:      "Andrey A. Chernov, Black Mage" <ache@astral.msk.su>
To:        Paul Traina <pst@shockwave.com>
Cc:        CVS-commiters@freefall.cdrom.com, cvs-libexec@freefall.cdrom.com
Subject:   Re: cvs commit: src/libexec/atrun atrun.man Makefile atrun.c atrun.8 atrun.h
Message-ID:  <iIzGvYlWW2@astral.msk.su>
In-Reply-To: <199504120314.UAA02122@precipice.shockwave.com>; from Paul Traina at Tue, 11 Apr 1995 20:14:38 -0700
References:  <199504120314.UAA02122@precipice.shockwave.com>

next in thread | previous in thread | raw e-mail | index | archive | help
In message <199504120314.UAA02122@precipice.shockwave.com> Paul Traina
    writes:

>Did you just upgrade to 2.7a?  2.7a does not actually fix the security hole,
>at least according to my examination of the distribution source code.

Yes, with my own more stronger checking (followed to author).
Original 2.7a still have hole on FreeBSD because setreuid()
don't change real uid.

>Also, I was a little concerned to see pathnames.h et al go away.  Has this
>program suddently gotten much less bsd-like in nature?

Less BSD-like, but more compatible with original version and
its future releases, it makes upgrade process more easy.
Really, Makefile.inc replace pathnames.h with defines for
original version.

-- 
Andrey A. Chernov        : And I rest so composedly,  /Now, in my bed,
ache@astral.msk.su       : That any beholder  /Might fancy me dead -
FidoNet: 2:5020/230.3    : Might start at beholding me,  /Thinking me dead.
RELCOM Team,FreeBSD Team :         E.A.Poe         From "For Annie" 1849



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?iIzGvYlWW2>