[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: user can't mount loop device...



On Fri, Jan 19, 2001 at 03:05:16PM -0500, Daniel Jacobowitz wrote:
> What no one has mentioned is that users absolutely MUST NOT be allowed
> to run losetup (or mount, which would also be necessary).  It's a file
> image.  It can, for instance, contain suid binaries, not owned by the
> user.  That's easy to make - see debugfs.

The Hurd wins again.

Marcus

-- 
`Rhubarb is no Egyptian god.' Debian http://www.debian.org brinkmd@debian.org
Marcus Brinkmann              GNU    http://www.gnu.org    marcus@gnu.org
Marcus.Brinkmann@ruhr-uni-bochum.de
http://www.marcus-brinkmann.de



Reply to: