OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Andreas Ferber (aferberTECHFAK.UNI-BIELEFELD.DE)
Date: Mon Feb 05 2001 - 13:40:09 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hi,

    On Mon, Feb 05, 2001 at 06:34:47AM -0500, John wrote:
    > On my Debian 2.2 system 'man' was installed
    > suid root. I don't know about Debian 2.3 but,
    > Debian 2.2 does install 'man' suid root.

    No, this is not true:

    $ ls -la /usr/lib/man-db/man
    -rwsr-xr-x 1 man root 82848 Apr 4 2000 /usr/lib/man-db/man
    $

    This is the actual man binary (/usr/bin/man is only a wrapper, did not
    examine closer what it does, but it has no setu/gid bit set), after a
    plain Debian 2.2 potato install.

    Andreas

    -- 
    After the last of 16 mounting screws has been removed from an access
    cover, it will be discovered that the wrong access cover has been removed.
    

    -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org

    iD8DBQE6fwGZfO23eTjctSoRAtYIAJ0QV9XbIPXEN5lciY8Sm+lcNya3NACfeUDk 3Vu6F14q91hhW5l9mzSVUes= =nA5s -----END PGP SIGNATURE-----