Brock Sides wrote: > Whereas majordomo 1.94.5 does fix the bug in resend, discovered by Brock > Tellier, that permits execution of arbitrary code as user majordomo, it > apparently does not fix the other bug in the script majordomo, that > permits execution of arbitrary config files as user majordomo: While people need to certainly be made clear of this, this is entirely intentional. The cleanest fix to the problem of the majordomo programs running arbitrary code as the majordomo user/group is to fix the permissions of the wrapper so it is mode o-rx. (or that the Majordomo home directory is mode mode 750) Any other proposed solutions were fraught with race conditions, partial fixes, and just plain uglinesses. This is clearly explained in the INSTALL document in 1.94.5 and re-emphasized on the Majordomo FAQ. --Dave Majordomo FAQ maintainer
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:31:23 PDT