[1172] in bugtraq
RE: set group id on directories (fwd)
daemon@ATHENA.MIT.EDU (Matthew Bontoft)
Fri Mar 3 19:01:30 1995
Date: Sat, 4 Mar 1995 08:34:37 +1000 (GMT+1000)
From: Matthew Bontoft <cs327953@student.uq.edu.au>
To: bugtraq@fc.net
On Fri, 3 Mar 1995, Marc Samama wrote:
>
> According to the replies i got so far, sgid bit on directories
> dont represent a risk. Then, I still wonder why tiger classifies this as an
> 'ALERT'?
Perhaps tiger (I haven't seen it so I can't say for sure) mistakes suid
bits on files with sgid bits on directories. I guess its an easy enough
error to make but it certainly does display some very poor programming.