Subject: Re: Fix for PR security/8069: man(1) vulnerability
To: Matthias Scheler <tron@zhadum.de>
From: Simon Burge <simonb@netbsd.org>
List: tech-security
Date: 07/26/1999 09:50:14
Matthias Scheler wrote:
> Hello,
>
> here is my suggestion for a fix for PR security/8069:
Maybe something like this should also be considered for libutil - is
there anywhere else this (or similiar) functionality might be used in
userland?
One drawback (sort of mentioned by Matt Green) is that this makes
"nobody" a standard account - it's in our example passwd file, but
that doesn't mean that some people don't delete it.
Simon.