NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: lib/50823: src/lib/libwrap/hosts_access.c:317: huge input data problem ?



The following reply was made to PR lib/50823; it has been noted by GNATS.

From: "Jeremy C. Reed" <reed%reedmedia.net@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc: 
Subject: Re: lib/50823: src/lib/libwrap/hosts_access.c:317: huge input data
 problem ?
Date: Mon, 22 Feb 2016 12:39:28 -0600 (CST)

 On Wed, 17 Feb 2016, dcb314%hotmail.com@localhost wrote:
 
 > This might be a security issue.
 
 Thanks again for reporting this. For the record, I received this from 
 one of the security officers: "This is not a security issue (unless 
 users other than root have write access to the /etc/hosts.{allow,deny} 
 files and the files that are referred from them, which is a security 
 issue itself), since the files parsed are under root control."
 


Home | Main Index | Thread Index | Old Index