Relay-Version: version B 2.10 5/3/83; site utzoo.UUCP Path: utzoo!watmath!clyde!burl!ulysses!bellcore!decvax!decwrl!pyramid!hplabs!hplabsc!taylor From: taylor@hplabsc.UUCP Newsgroups: net.sources.bugs Subject: Security bugs in Msg (info wanted) Message-ID: <8800003@hplabsc.UUCP> Date: Fri, 23-May-86 14:19:00 EDT Article-I.D.: hplabsc.8800003 Posted: Fri May 23 14:19:00 1986 Date-Received: Sun, 25-May-86 12:35:08 EDT References: <667@eneevax.UUCP> Organization: Hewlett-Packard Laboratories - Palo Alto, CA Lines: 15 > I just brought up the Msg mail system and was informed that were some > security bugs in it. I was wondering if someone would send me the > fixes. I tried to send mail to the author, it didn't work. I also > tried the moderator of mod.sources and didn't get a reply. Well...the problem with the version of Msg posted is that it doesn't correctly check for permissions on files to append to or to read. There is, however, a new version in the works that fixes the problems. In the meantime, use it setgid instead of setuid. -- Dave Taylor ..hplabs!taylor