Y
Hacker News
new
|
ask
|
show
|
jobs
by
ranguski
1722 days ago
Damn, this is amazing. Even as bare access goes. Find is indeed a severity red, unsure who is gonna patch up mailutils
1 comments
joeyh
1721 days ago
I'm going to guess "noone". This is not the first security hole like this caused by piping to mail. See CVE-2000-0703, a trivial local root via suidperl. Unfortunately backwards compatability often wins over prevention of future security holes.
link