Subject: Re: Fix for PR security/8069: man(1) vulnerability
To: Matthias Scheler <tron@zhadum.de>
From: Simon Burge <simonb@netbsd.org>
List: tech-security
Date: 07/26/1999 09:50:14
Matthias Scheler wrote:

> 	Hello,
> 
> here is my suggestion for a fix for PR security/8069:

Maybe something like this should also be considered for libutil - is
there anywhere else this (or similiar) functionality might be used in
userland?

One drawback (sort of mentioned by Matt Green) is that this makes
"nobody" a standard account - it's in our example passwd file, but
that doesn't mean that some people don't delete it.

Simon.