Home page logo

bugtraq logo Bugtraq mailing list archives

Re: Troff dangerous.
From: imp () VILLAGE ORG (Warner Losh)
Date: Tue, 27 Jul 1999 10:36:01 -0600

In FreeBSD-stable and -current, these tricks allow only tojan horses,
but do not allow normal users to elevate their privs.  It appears that
man doesn't run at elevated priviledge levels for execution of the
sub-commands needed to build the man pages (despite man being setuid
man on FreeBSD-stable/current).

I just noticed that OpenBSD added a -S flag which completely disables
these commands...  I think I like that, in conjunction with having man
use that flag...


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]