In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes:
>On Sat, Aug 02, 2003 at 02:51:03PM -0500, Steve Greenland wrote:
>Under this setup, when cron opens a crontab file, it should fstat() it and
>check that it is owned by the uid under which its contents will be executed
>before trusting it.

It should not trust symbolic links either.  Otherwise it instanly promotes
everything that looks like a crontab into one.


-- 
Blars Blarson                   [EMAIL PROTECTED]
                                http://www.blars.org/blars.html
"Text is a way we cheat time." -- Patrick Nielsen Hayden


Reply via email to