Bugtraq mailing list archives

Re: [RHSA-1999:030-01] Buffer overflow in cron daemon


From: Todd.Miller () COURTESAN COM (Todd C. Miller)
Date: Sat, 28 Aug 1999 11:10:35 -0600


Why not just have sendmail run as the user who owns the crontab?
I see no credible reason to run it as root.  This is fairly simple
as do_command and cron_popen are only used to send mail anyway.

Doing sanity checks on your input is all well and good but there's
no guarantee you will catch everything.

 - todd


Current thread: