Re: Linux /usr/bin/gnuplot overflow

From: Marc Heuse (marcat_private)
Date: Mon Mar 08 1999 - 14:03:23 PST

  • Next message: SGI Security Coordinator: "X server font path buffer overflow vulnerability"

    Hi!
    
    > > /etc/rc.config and set PERMISSION_SECURITY="paranoid". That way gnuplot
    >
    > warning, warning.
    >
    > permissions.paranoid is not supported by SuSE --- it was contributed
    > by me. It only fixes the problems that SuSE 5.0 had. When I have
    > some time again, I will do the same work with a full install of
    > SuSE 6.0.
    
    this is true but not bad. This just means that there are no additional
    programs which get the suid bit. thats okay ;-)
    
    > At least without clear information from SuSE that /etc/permissions.paranoid
    > is uptodate, I would not count on it to be _absolutely_ paranoid.
    > After all, you are supposed to do your homeworks yourself, too :)
    >
    > Also, for it to work, it needs a few things, such as an ``xok'' group,
    > etc, look at the start of that file.
    
    no. I "xok" "trusted" etc. groups are now part of the standard SuSE
    distribution
    
    Greets,
    	Marc
    --
      Marc Heuse, S.u.S.E. GmbH, Schanzaeckerstr. 10, 90443 Nuernberg
      E@mail: marcat_private      Function: Security Support & Auditing
      issue a  "finger marcat_private | pgp -fka" for my public pgp key
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:38:17 PDT