Re: [linux-alert] Serious Security hole in getpwnam ()
From: kai@khms.westfalen.de (Kai Henningsen)
> As it appears only very few developers are on these lists, here's an
> important security alert.
This list is gatewayed to usenet. :-)
> +username::::::
Barf with a spoon. It breaks my system.
I submit that the attached fix is insufficient and that
passwd entries that do not contain UID and GID numbers should not be
returned by the various password library functions.
Thanks
Bruce
--
Pixar's Toy Story: Over 1/3 Billion dollars world box office so far.
Bruce Perens AB6YM Bruce@Pixar.com http://www.hams.com/
Reply to: