|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)
Subject: Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)
From: Roman Drahtmueller (draht
uni-freiburg.de)
Date: Wed Jan 19 2000 - 01:21:51 CST
- Next message: Erwin S. Andreasen: "Re: [suse-security] printenv, info2html - default setup in SuSE allow unwanted disclosure of information."
- Previous message: back up account: "[suse-security] printenv, info2html - default setup in SuSE allow unwanted disclosure of information."
- In reply to: Oliver Leue: "[suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Next in thread: Andreas Siegert: "Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Next in thread: Thomas Michael Wanka: "Re: [suse-security] netscape call chown"
- Reply: Roman Drahtmueller: "Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
> >> today i found that netscape calls "chown".
>
> not chown, but chmod.
>
> > Send bug reports concerning non-open-source programs to the authors.
> > We can't fix bugs w/o source code.
>
> that's what i did. send it to netscape.
>
> but that's not only a bug. it's a security-hole too isn't it?
I still wonder where the problem is with that. While it may be a nasty
habit to do a system("chmod...") instead of chmod(2), I don't see a
security-related problem unless the PATH is messed up.
And since I'm certain that users don't run netscape as root (*g*), the
chown shouldn't do any harm, too.
Roman.
-- _ _ | Roman Drahtmüller "Freedom means that you can choose | CC University of Freiburg what you want to learn at a given | email: drahtuni-freiburg.de time." A. Becker, 1999 | - - People often find it easier to be a result of the past than a cause of the future.
--------------------------------------------------------------------- To unsubscribe, e-mail: suse-security-unsubscribe
suse.com For additional commands, e-mail: suse-security-help
suse.com
- Next message: Erwin S. Andreasen: "Re: [suse-security] printenv, info2html - default setup in SuSE allow unwanted disclosure of information."
- Previous message: back up account: "[suse-security] printenv, info2html - default setup in SuSE allow unwanted disclosure of information."
- In reply to: Oliver Leue: "[suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Next in thread: Andreas Siegert: "Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Next in thread: Thomas Michael Wanka: "Re: [suse-security] netscape call chown"
- Reply: Roman Drahtmueller: "Re: [suse-security] Correction: was :(re: [suse-security] netscape call chown)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Wed Jan 19 2000 - 01:23:12 CST