From owner-cvs-all Wed Jul 5 19:58:28 2000 Delivered-To: cvs-all@freebsd.org Received: from whizzo.transsys.com (whizzo.TransSys.COM [144.202.42.10]) by hub.freebsd.org (Postfix) with ESMTP id 1D93E37C01C; Wed, 5 Jul 2000 19:58:22 -0700 (PDT) (envelope-from louie@whizzo.transsys.com) Received: from whizzo.transsys.com (localhost.transsys.com [127.0.0.1]) by whizzo.transsys.com (8.9.3/8.9.1) with ESMTP id WAA21955; Wed, 5 Jul 2000 22:58:20 -0400 (EDT) (envelope-from louie@whizzo.transsys.com) Message-Id: <200007060258.WAA21955@whizzo.transsys.com> X-Mailer: exmh version 2.1.1 10/15/1999 To: Kris Kennaway Cc: "Jordan K. Hubbard" , Jean-Marc Zucconi , Alfred Perlstein , cvs-committers@FreeBSD.ORG, cvs-all@FreeBSD.ORG X-Image-URL: http://www.transsys.com/louie/images/louie-mail.jpg From: "Louis A. Mamakos" Subject: Re: cvs commit: ports/x11/XFree86-4 Makefile References: In-reply-to: Your message of "Wed, 05 Jul 2000 13:46:25 PDT." Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Wed, 05 Jul 2000 22:58:20 -0400 Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG > On Wed, 5 Jul 2000, Jordan K. Hubbard wrote: > > > > They have fixed the _known_ holes but the server is still setuid > > > root so the possibility of undiscovered security bugs remains. > > > > Which is all that can be said for *any* setuid root binary in FreeBSD. :-) > > We don't have any setuid root binaries which are this complex and fearsome > :-) Uh, -r-sr-xr-x 1 root wheel 316348 Jun 5 22:16 /usr/libexec/sendmail/sendmail* I'm not sure if I fear X or sendmail more, but it's pretty close! louie To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message