Bugtraq mailing list archives

Re: [linux-security] Re: Possible bufferoverflow condition in


From: fox () mailhost rsn hp com (David DeSimone)
Date: Wed, 14 Aug 1996 17:54:55 -0500


Digital Dreamer <dreamer () garrison inetcan net> wrote:

  On the same note, after all the problems with sendmail, why does it
still need suid to operate?

Sendmail needs to be root in order to become another user, for example,
to run any pipe programs indicated in the .forward file.  It wouldn't do
to have those programs run as the user who was sending the mail.

Naturally, some other scheme could probably be concocted to avoid having
sendmail immediately be root, or to have some other daemon perform final
delivery if the uid needs to be changed, but that's going to probably be
a major design change.

--
David DeSimone    | "The doctrine of human equality reposes on this:
fox () convex hp com |  that there is no man really clever who has not
Hewlett-Packard   |  found that he is stupid." -- Gilbert K. Chesterson
Convex Division   |      PGP: 5B 47 34 9F 3B 9A B0 0D  AB A6 15 F1 BB BE 8C 44



Current thread: