Re: PAM exec patch to allow PAM_AUTHTOK to be exported.

看板FB_security作者時間18年前 (2007/05/21 01:12), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/10 (看更多)
"Zane C.B." <v.velox@vvelox.net> writes: > Dag-Erling Sm=C3=B8rgrav <des@des.no> writes: >> Your patch opens a gaping security hole. Sensitive information >> should never be placed in the environment. > Unless I am missing something, this is only dangerous if one is doing > something stupid with what ever is being executed by pam_exec. Environment variables may be visible to other processes and users through e.g. /proc. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #16K85z00 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #16K85z00 (FB_security)