It is a poor trade.

Giving a user an additional gid or uid (for program lifetime), in
programs which have not been reviewed (or -- cannot be reviewed and
fixed), is not good.

Before, setgid games could be used along with another bug to fill /var.

Now, you can just fill /var because you made it writeable to all.

You are making this program give the user an ability that didn't exist
before.  The ability to fill /var. 

Shit breaks pretty badly when /var is full.

Score files in this garbage program are not important enough to create
that risk for users.

Reply via email to