[net.sources.bugs] Security bugs in Msg

phaedrus@eneevax.UUCP (Praveen Kumar) (05/21/86)

I just brought up the Msg mail system and was informed that were some
security bugs in it.  I was wondering if someone would send me the
fixes.  I tried to send mail to the author, it didn't work.  I also
tried the moderator of mod.sources and didn't get a reply.

Thanks,
pk
-- 
"Everybody wants a piece of pie, today," he said.
"You gotta watch the ones who always keep their hands clean."

phaedrus@eneevax.umd.edu or {seismo,allegra}!umcp-cs!eneevax!phaedrus

taylor@hplabsc.UUCP (05/23/86)

> I just brought up the Msg mail system and was informed that were some
> security bugs in it.  I was wondering if someone would send me the
> fixes.  I tried to send mail to the author, it didn't work.  I also
> tried the moderator of mod.sources and didn't get a reply.

Well...the problem with the version of Msg posted is that it doesn't
correctly check for permissions on files to append to or to read.

There is, however, a new version in the works that fixes the problems.

In the meantime, use it setgid instead of setuid.

					-- Dave Taylor

					..hplabs!taylor