|
Bugtraq
mailing list archives
Re: Troff dangerous.
From: imp () VILLAGE ORG (Warner Losh)
Date: Tue, 27 Jul 1999 10:36:01 -0600
In FreeBSD-stable and -current, these tricks allow only tojan horses,
but do not allow normal users to elevate their privs. It appears that
man doesn't run at elevated priviledge levels for execution of the
sub-commands needed to build the man pages (despite man being setuid
man on FreeBSD-stable/current).
I just noticed that OpenBSD added a -S flag which completely disables
these commands... I think I like that, in conjunction with having man
use that flag...
Warner
By Date
By Thread
Current thread:
- Trojan Horse Guard - Cassandra GOLD Release., (continued)
|