Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 2 Nov 1998 00:15:40 -0500 (EST)
From:      "Matthew N. Dodd" <winter@jurai.net>
To:        Brett Glass <brett@lariat.org>
Cc:        "Jan B. Koum " <jkb@best.com>, Peter Jeremy <peter.jeremy@auss2.alcatel.com.au>, freebsd-security@FreeBSD.ORG
Subject:   Re: SSH vsprintf patch. (You've been warned Mr. Glass)
Message-ID:  <Pine.BSF.4.02.9811020014040.17054-100000@sasami.jurai.net>
In-Reply-To: <4.1.19981101213518.0462e910@127.0.0.1>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 1 Nov 1998, Brett Glass wrote:
> What does this argument do? (Yes, I've already applied patches and also
> replaced a few sprintf()s.

The client is installed suid root (for various reasons).  The option in
question disables this behavior.

As sshd is binding and listening to a port below 1024 it must run as root.

The alleged problem with sshd lies in the code that logs connections etc.


-- 
| Matthew N. Dodd  | 78 280Z | 75 164E | 84 245DL | FreeBSD/NetBSD/Sprite/VMS |
| winter@jurai.net |      This Space For Rent     | ix86,sparc,m68k,pmax,vax  |
| http://www.jurai.net/~winter | Are you k-rad elite enough for my webpage?   |


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.02.9811020014040.17054-100000>