Subject: Re: setuid, core dumps, ftpd, and DB
To: None <thorpej@nas.nasa.gov>
From: Jon Ribbens <jon@oaktree.co.uk>
List: tech-userlevel
Date: 10/21/1996 17:21:37
Jason Thorpe wrote:
>  > > * In the particular case of ftpd, if you've logged in as a user other
>  > > than root, then your saved, real, and effective uids do not match, so
>  > > the previous check we used to use (ruid != svuid || ruid != euid)
>  > > would catch this.  So, unless you're logged in as root, you'd be hard
>  > > pressed to get ftpd to core dump.
>  > 
>  > (except on 1.1, when it's easy)
> 
> In which case you should either:
> 
> 	* Upgrade to a more recent release, or
> 
> 	* modify your kern_sig.c to perform the same check as
> 	  NetBSD-current's kern_sig.c.

Well, yes, I know that, and I've done the second option. But there's
bound to be a lot of people using 1.1 for a long time yet.

Cheers


Jon
____
\  //    Jon Ribbens    //
 \// jon@oaktree.co.uk //