"Mayers, Philip J" wrote:

> I typically turn anything using it off,
> since there are mile-wide holes in most Unices handling of ONC/RPC (sun
> calendar manager, anyone?).

Fixed a long time ago. But then you should not be running
anything you do not need on any machine as there can
always have unknown security problems, whatever the
OS or protocol.

> (That's not to say the same isn't true of DCE/RPC...)

Buffer overflow problems are a problem in any library
if they are not programed around in the first place.

> I personally regard a generic, transport independent DCE/RPC library as a
> good thing from an engineering point of view.


