[geeks] Selling points

alex j avriette avriettea at speakeasy.net
Sat Apr 27 10:03:04 CDT 2002


>> Seriously, sudo (and its ilk) is a security bug waiting for an exploit
>> (as has recently been discussed on the netbsd lists....  ;-)
>
> You are aware of the buffer overflow (yes, a buffer overflow! Furrfu!) 
> that
> was reported in sudo recently?

Yes. I *HATE* sudo for this reason. Everyone tells me how wonderful it 
is and that i should be using it instead of whatever great lengths im 
going to to avoid it at the time. The problem with sudo is that it has 
been a MAJOR cause of local root exploits, including in openbsd, which I 
generally trust to be secure.

alex



More information about the geeks mailing list