Re: Whom the BIND newest vulnerability concerns?
Tomasz Papszun <tomek@lodz.tpsa.pl> wrote:
>
> Theoritically, there could be some DoS-type interference - when one
> program would create a pid-file normally used by another program.
> But - as you pointed out - they usually run as root so they could do
> bigger damages if they were compromised, anyway.
Yes but when you do this, those daemons that are now group daemon and not run
as root can create pid files for all daemons with pid files in /var/run if
they haven't started yet.  IMHO this is undesirable and is easily avoided by
having a subdirectory.
-- 
Debian GNU/Linux 2.1 is out! ( http://www.debian.org/ )
Email:  Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Reply to: