*BSD News Article 73183


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!harbinger.cc.monash.edu.au!nntp.coast.net!news.kei.com!news.mathworks.com!fu-berlin.de!zrz.TU-Berlin.DE!news.tu-chemnitz.de!irz401!orion.sax.de!uriah.heep!news
From: j@uriah.heep.sax.de (J Wunsch)
Newsgroups: comp.mail.elm,comp.unix.bsd.freebsd.misc
Subject: Re: elm 2.4 and FreeBSD
Date: 8 Jul 1996 20:49:41 GMT
Organization: Private BSD site, Dresden
Lines: 16
Message-ID: <4rrs95$1eu@uriah.heep.sax.de>
References: <jmanley-2906960000510001@fw42.metronet.com>
  <4r3peo$s7j@uriah.heep.sax.de> <31D6C791.4746@me.pvamu.edu>
  <4rc156$crm@uriah.heep.sax.de> <4rgt5c$scg@news3.realtime.net>
Reply-To: joerg_wunsch@uriah.heep.sax.de (Joerg Wunsch)
NNTP-Posting-Host: localhost.heep.sax.de
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Newsreader: knews 0.9.6
X-Phone: +49-351-2012 669
X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F  93 21 E0 7D F9 12 D6 4E
Xref: euryale.cc.adfa.oz.au comp.mail.elm:19683 comp.unix.bsd.freebsd.misc:23112

chip@unicom.com (Chip Rosenthal) wrote:

> >Because it requires elm to run setgid
> 
> Not if you set the sticky bit on the mail spool.

That's even more ugly.  Don't do it, there are known races that can be
abused.  (At least, that's what the security officers had to say about
it... ;)

-- 
cheers, J"org

joerg_wunsch@uriah.heep.sax.de -- http://www.sax.de/~joerg/ -- NIC: JW11-RIPE
Never trust an operating system you don't have sources for. ;-)