Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Dec 2011 11:25:22 -0600
From:      Stephen Montgomery-Smith <stephen@missouri.edu>
To:        freebsd-stable@freebsd.org
Subject:   Re: FLAME - security advisories on the 23rd ? uncool idea is uncool
Message-ID:  <4EF4B982.3070207@missouri.edu>
In-Reply-To: <4EF4B2D6.5090206@sentex.net>
References:  <4EF4A75C.2040609@my.gd> <4EF4B2D6.5090206@sentex.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On 12/23/2011 10:56 AM, Mike Tancsa wrote:

> Also, the chroot issue has been public for some time along with sample
> exploits. Same with BIND which was fixed some time ago.  Judgment call,
> and I think they made the right call at least from my perspective.

It is this chroot issue that bothers me.  From my reading of the ftpd 
man page, if I have anonymous ftp to my server, it seems that I am using 
chroot with ftpd, and there is no way to stop this happening.

Am I correct, or have I missed something?  (I am hoping I missed something.)



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4EF4B982.3070207>