[9949] in bugtraq
Re: /usr/bin/doscmd on BSDI
daemon@ATHENA.MIT.EDU (Keith Bostic)
Thu Mar 18 15:22:40 1999
Date: Thu, 18 Mar 1999 12:16:03 -0500
Reply-To: Keith Bostic <bostic@BSDI.COM>
From: Keith Bostic <bostic@BSDI.COM>
To: BUGTRAQ@NETSPACE.ORG
I don't believe that there is a security problem in doscmd. By the time
that doscmd can be affected by an overflow, permissions have been re-set
to the user's, with no dangerous file descriptors open.
(That's not to say the buffer overflows shouldn't be fixed, of course.)
Regards,
--keith
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Keith Bostic bostic@bsdi.com