On Mon, 10 Jun 2002, Binand Raj S. wrote:

> Authentication is done against /etc/shadow, which is usually
> readable only by root. Hence su should be setuid root.

I would think all authentication would be done by consolehelper (through 
pam), which is setuid root anyway.

But then RH 6 a long time ago (will check at home), and consolehelper
did have a local root exploit back then (allowed .. in the path to a
conf file, which in turn could refer to any library which would run as
root).

-- 
"Don't think; let the machine do it for you!"
-- E. C. Berkeley


_______________________________________________________________

Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas - 
http://devcon.sprintpcs.com/adp/index.cfm?source=osdntextlink

_______________________________________________
linux-india-help mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/linux-india-help

Reply via email to