[5182] in bugtraq
/bin/eject
daemon@ATHENA.MIT.EDU (Matt Potter)
Tue Aug 26 17:35:42 1997
Date: Fri, 22 Aug 1997 21:59:28 -0400
Reply-To: Matt Potter <mpotter@INTR.NET>
From: Matt Potter <mpotter@INTR.NET>
X-To: "Serge E. Pick" <sep@beta.niimm.spb.su>
To: BUGTRAQ@NETSPACE.ORG
>
> Eject can be runned by any user too. After that try to
Ejects works SUID root and as well w/o SUID bit, IF volume managment is
running. So if you run volume management you can remove the SUID bit on
/bin/eject.... one less SUID proggie to worry about. Any user can eject
media if it's not currently being used... I could imagine possible
annoyances with this... some one ejecting your floppy while your home
and having to drive back to the office to put the damn thing back in.
Matt