Subject: Re: CVS commit: basesrc
To: Perry E. Metzger <perry@piermont.com>
From: Hubert Feyrer <feyrer@rfhs8012.fh-regensburg.de>
List: source-changes
Date: 07/26/1999 22:57:07
On 26 Jul 1999, Perry E. Metzger wrote:
> > Log Message:
> > Use "groff -S -Tascii" instead of "nroff" to avoid security problems
> > if "man" is used by "root". Fixes PR security/8069 by Matthias Buelow.
> 
> This really didn't fix the entire problem.
> 
> In general, groff should be rigged so that "-S" is the default, and a
> new option added to turn *off* that functionality.  Otherwise, every
> time anyone troff's a document a potential disaster might occur.

Maybe have a look how OpenBSD fixed this?


 - Hubert

-- 
NetBSD - Better for your uptime than Viagra