Subject: Re: Fix for PR security/8069: man(1) vulnerability
To: None <tech-security@netbsd.org>
From: Matthias Scheler <tron@zhadum.de>
List: tech-security
Date: 07/26/1999 07:24:02
In article <199907260536.HAA08629@orade.oreilly.de>,
	Christoph Badura <bad@oreilly.de> writes:
>>	balrog:~ 5280> grep daemon /NetBSD/src/etc/mtree/NetBSD.dist
>>	msgs            uname=daemon

What's the purpose of that directory after all?

>>	lock            uname=uucp gname=daemon
>>	uucp            uname=uucp gname=daemon
>>	uucppublic      uname=uucp gname=daemon mode=01777
> 
> At least the last three a gname=uucp on sane systems.

I would like to see a group "uucp", too. But AFAIK we don't have an
automatical mechanism to add missing groups. Thus people will need
to do it manually during their next update. Do we want that?

	Kind regards

-- 
Matthias Scheler                                http://home.owl.de/~tron/