From owner-freebsd-security Wed Nov 21 12: 8:57 2001 Delivered-To: freebsd-security@freebsd.org Received: from lazir.toya.net.pl (lazir.toya.net.pl [217.113.224.3]) by hub.freebsd.org (Postfix) with SMTP id CCE3637B416 for ; Wed, 21 Nov 2001 12:08:53 -0800 (PST) Received: (qmail 28956 invoked by uid 791); 21 Nov 2001 20:05:41 -0000 Received: from localhost (sendmail-bs@127.0.0.1) by localhost with SMTP; 21 Nov 2001 20:05:41 -0000 Date: Wed, 21 Nov 2001 21:05:41 +0100 (CET) From: To: Bart Matthaei Cc: The Anarcat , Subject: Re: fun with pkg_add In-Reply-To: <20011121205519.A16928@heresy.dreamflow.nl> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Well the problem exists, it should have 700 permissions. The only problem is time, and you dont know what kind of package is beeing installed right now so exploiting is reather easy but problematical. Regards. airot.. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message