Date: Wed, 11 Dec 1996 00:57:35 -0800 From: Paul Traina <pst@shockwave.com> To: "Andrey A. Chernov" <ache@freefall.freebsd.org> Cc: CVS-committers@freefall.freebsd.org, cvs-all@freefall.freebsd.org, cvs-ports@freefall.freebsd.org Subject: Re: cvs commit: ports/comms/kermit/patches patch-ab Message-ID: <199612110857.AAA23163@precipice.shockwave.com> In-Reply-To: Your message of "Tue, 10 Dec 1996 12:32:20 PST." <199612102032.MAA27653@freefall.freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
That's not a security hole. If you don't like the behavior, just don't setgid dialer the program. Paul From: "Andrey A. Chernov" <ache@freefall.freebsd.org> Subject: cvs commit: ports/comms/kermit/patches patch-ab ache 96/12/10 12:32:19 Added: comms/kermit/patches patch-ab Log: Close small security hole introduced with last upgrade (one needed patch not applied): anyone (not dialer group members only) can do anything with serial devices
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199612110857.AAA23163>