Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 10 Feb 1996 11:06:43 -0500 (EST)
From:      Howard Goldstein <hg@penny.n2wx.ampr.org>
Cc:        FREEBSD-SECURITY-L <freebsd-security@FreeBSD.org>
Subject:   Re: User creating root-owned directories? 
Message-ID:  <Pine.LNX.3.91.960210110352.492B-100000@n2wx.ampr.org>
In-Reply-To: <199602100808.AAA02008@precipice.shockwave.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, 10 Feb 1996, Paul Traina wrote:

> In any case, I'd upgrade to sendmail 8.7.x (x=current) and freebsd 2.1
> -stable just to be sure you've got all the security patches.  8.6.12 does
> have bugs in it which could allow a user to gain root.

I'd also suggest use of the 'smrsh' restricted shell on sendmail-invoked
processes to help keep security on sendmail up to snuff as future holes
are discovered (see smrsh subdir in the sendmail distrib). 

-- 
Howard Goldstein        <hg@n2wx.ampr.org>         http://www.tapr.org/~n2wx/
mail/newsadmin @mpcs.com




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.3.91.960210110352.492B-100000>