smbsh issues w/ samba-2.0.7

David Collier-Brown David.Collier-Brown at canada.sun.com
Fri Nov 3 17:39:08 GMT 2000


Steve Langasek wrote:
> But if a setuid program could be invoked with an insecure library listed in
> LD_PRELOAD, that would also be a security problem

	Absolutely, and I understand their concern.  Alas, the
	fix wasn't actually a fix (:-()

--dave
-- 
David Collier-Brown,  | Always do right. This will gratify some people
185 Ellerslie Ave.,   | and astonish the rest.        -- Mark Twain
Willowdale, Ontario   | //www.oreilly.com/catalog/samba/author.html
Work: (905) 415-2849 Home: (416) 223-8968 Email: davecb at canada.sun.com




More information about the samba-technical mailing list