Subject: Re: Bugtraq: procfs hole
To: Andrew Brown <codewarrior@daemon.org>
From: Eduardo E. Horvath <eeh@one-o.com>
List: tech-security
Date: 08/15/1997 08:50:13
On Fri, 15 Aug 1997, Andrew Brown wrote:

> wouldn't a simpler solution be to basically effect a revoke(2) on the
> "file descriptor" or "vnode" associated with the mem pseudo-file on
> each process before it does the exec (maybe even only do this if the
> exec is calling a suid program)?  this could be placed in the exec
> subsystem...

I would have thought unlink()ing the old image and link()ing the new
image under the same name waould be the proper semantics.  That's
basically what exec does anyway, isn't it?  Oh, for a unified buffer
cache...

=========================================================================
Eduardo Horvath				eeh@btr.com
"Cliffs are for climbing.  That's why God invented grappling hooks."
					- Benton Frasier