Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 10 Aug 2010 18:39:28 +0300
From:      Jaakko Heinonen <jh@FreeBSD.org>
To:        Janne Snabb <snabb@epipe.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: ~/.login_conf mechanism is flawed
Message-ID:  <20100810153928.GA28619@jh>
In-Reply-To: <alpine.BSF.2.00.1008100841350.96753@tiktik.epipe.com>

index | next in thread | previous in thread | raw e-mail

On 2010-08-10, Janne Snabb wrote:
> Looks like the per-user login capability database (~/.login_conf,
> ~/.login_conf.db) functionality is creating a vulnerability.

See also PR bin/141840:

	http://www.freebsd.org/cgi/query-pr.cgi?pr=141840

-- 
Jaakko


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20100810153928.GA28619>