[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [linux-alert] Serious Security hole in getpwnam ()



From: kai@khms.westfalen.de (Kai Henningsen)

> As it appears only very few developers are on these lists, here's an  
> important security alert.

This list is gatewayed to usenet. :-)

>  +username::::::

Barf with a spoon. It breaks my system.

I submit that the attached fix is insufficient and that
passwd entries that do not contain UID and GID numbers should not be
returned by the various password library functions.

	Thanks

	Bruce
--
Pixar's Toy Story: Over 1/3 Billion dollars world box office so far.

Bruce Perens AB6YM          Bruce@Pixar.com            http://www.hams.com/


Reply to: