From owner-cvs-libexec Wed Apr 12 02:20:26 1995 Return-Path: cvs-libexec-owner Received: (from majordom@localhost) by freefall.cdrom.com (8.6.10/8.6.6) id CAA05234 for cvs-libexec-outgoing; Wed, 12 Apr 1995 02:20:26 -0700 Received: from sequent.kiae.su (sequent.kiae.su [144.206.136.6]) by freefall.cdrom.com (8.6.10/8.6.6) with SMTP id CAA05225 ; Wed, 12 Apr 1995 02:20:11 -0700 Received: by sequent.kiae.su id AA15869 (5.65.kiae-2 ); Wed, 12 Apr 1995 13:02:02 +0400 Received: by sequent.KIAE.su (UUMAIL/2.0); Wed, 12 Apr 95 13:02:02 +0400 Received: (from ache@localhost) by astral.msk.su (8.6.8/8.6.6) id MAA00627; Wed, 12 Apr 1995 12:50:05 +0400 To: Paul Traina Cc: CVS-commiters@freefall.cdrom.com, cvs-libexec@freefall.cdrom.com References: <199504120314.UAA02122@precipice.shockwave.com> In-Reply-To: <199504120314.UAA02122@precipice.shockwave.com>; from Paul Traina at Tue, 11 Apr 1995 20:14:38 -0700 Message-Id: Organization: Olahm Ha-Yetzirah Date: Wed, 12 Apr 1995 12:50:05 +0400 X-Mailer: Mail/@ [v2.32 FreeBSD] From: "Andrey A. Chernov, Black Mage" X-Class: Fast Subject: Re: cvs commit: src/libexec/atrun atrun.man Makefile atrun.c atrun.8 atrun.h Lines: 23 Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Content-Length: 1001 Sender: cvs-libexec-owner@freebsd.org Precedence: bulk In message <199504120314.UAA02122@precipice.shockwave.com> Paul Traina writes: >Did you just upgrade to 2.7a? 2.7a does not actually fix the security hole, >at least according to my examination of the distribution source code. Yes, with my own more stronger checking (followed to author). Original 2.7a still have hole on FreeBSD because setreuid() don't change real uid. >Also, I was a little concerned to see pathnames.h et al go away. Has this >program suddently gotten much less bsd-like in nature? Less BSD-like, but more compatible with original version and its future releases, it makes upgrade process more easy. Really, Makefile.inc replace pathnames.h with defines for original version. -- Andrey A. Chernov : And I rest so composedly, /Now, in my bed, ache@astral.msk.su : That any beholder /Might fancy me dead - FidoNet: 2:5020/230.3 : Might start at beholding me, /Thinking me dead. RELCOM Team,FreeBSD Team : E.A.Poe From "For Annie" 1849