Subject: Re: chroot jail for ftpd
To: None <tls@rek.tjls.com>
From: Perry E. Metzger <perry@wasabisystems.com>
List: tech-security
Date: 10/17/2001 22:12:21
Thor Lancelot Simon <tls@rek.tjls.com> writes:
> Fixing this would require not allowing executable mappings if the backing
> vnode weren't executable.  I think that this is actually unquestionably
> correct, but because the original Sun implementation didn't require it,
> we will get zillions of complaints from people who say that we "broke
> shared libraries".

So we tell people with giant large letters to  chmod +x /usr/lib/lib*so.*
and be done with it. Better than leaving this go forever.

Perry
--
Perry E. Metzger		perry@wasabisystems.com
--
NetBSD Development, Support & CDs. http://www.wasabisystems.com/