Paul Phillips wrote:
>
> > there was a race condition in archive2.pl that
> > would allow any majordomo owned file to be appended to.
>
> Quick note -- just so nobody underestimates the need to upgrade, it's
> worse than a race condition. Race conditions popped up in the
> course of fixing it, but the hole that exists allows Bad Guys to modify
> arbitrary majordomo-owned files, without racing to do so.
If we don't want to upgrade the entire system, can we just drop
in the new archive2.pl over the old one?
I'm hesitant to upgrade because of all the problems I had getting
1.92 running right..
--
Michael Nelson nelson@seahunt.imat.com
San Francisco, CA FAX: 1-415-621-2608
www home page: http://seahunt.imat.com/nelson.html
Follow-Ups:
References:
|
|