Subject: Re: Shared libraries and crypt
To: None <michaelv@iastate.edu>
From: None <genehi@pactitle.com>
List: current-users
Date: 03/17/1994 21:47:33
"Michael L. VanLoon -- Iowa State University" <michaelv@iastate.edu> writes:
- The disadvantage is that if someone on your box can coax any security
- hole to write something over your shared libcrypt or to write
- something into that area of memory, everything on your box is suddenly
- compromised.  Crypt should not be shared.

A shared libcrypt is a security hole only when a security hole exists
to overwrite it.  If such a security hole already exists, libcrypt is
the least of your problems.

Leave it shared.

-- Gene


------------------------------------------------------------------------------