[20719] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Mail delivery privileges (was: Solaris /usr/bin/mailx exploit)

daemon@ATHENA.MIT.EDU (Dan Stromberg)
Sat May 19 16:51:43 2001

Date: Fri, 18 May 2001 18:16:09 -0700
From: Dan Stromberg <strombrg@nis.acs.uci.edu>
To: Olaf Kirch <okir@caldera.de>
Cc: Wietse Venema <wietse@porcupine.org>, bugtraq@securityfocus.com
Message-ID: <20010518181609.E15034@seki.acs.uci.edu>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-md5;
	protocol="application/pgp-signature"; boundary="z3ND3gJe4e1E4uwh"
Content-Disposition: inline
In-Reply-To: <20010518233404.A29631@monad.caldera.de>; from okir@caldera.de on Fri, May 18, 2001 at 11:34:04PM +0200


--z3ND3gJe4e1E4uwh
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Fri, May 18, 2001 at 11:34:04PM +0200, Olaf Kirch wrote:
> The only functionality you lose with flock is the ability to remotely
> mount your mail spool via NFS; but you shouldn't be doing this anyway.

This is pretty important functionality - certainly not something an
MTA author wants to give up for all his or her users.

Note that you don't really have to be able to deliver into NFS, just
be able to read mail over NFS - but even giving that up would limit an
MTA author's audience.

--=20
Dan Stromberg                                               UCI/NACS/DCS

--z3ND3gJe4e1E4uwh
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.5 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE7BclZo0feVm00f/8RAmmRAJ41IfWRzltGV2cORndfN9RW7cFz2wCfVlP0
84FecT2ZgyjwSIsJEUVJm+E=
=UWe3
-----END PGP SIGNATURE-----

--z3ND3gJe4e1E4uwh--

home help back first fref pref prev next nref lref last post