~/.login_conf mechanism is flawed

Jaakko Heinonen jh at FreeBSD.org
Tue Aug 10 15:55:02 UTC 2010


On 2010-08-10, Janne Snabb wrote:
> Looks like the per-user login capability database (~/.login_conf,
> ~/.login_conf.db) functionality is creating a vulnerability.

See also PR bin/141840:

	http://www.freebsd.org/cgi/query-pr.cgi?pr=141840

-- 
Jaakko


More information about the freebsd-security mailing list