[comp.sources.d] Bug in movemail?

amanda@iesd.auc.dk (Per Abrahamsen) (02/12/91)

>>>>> On 12 Feb 91 01:19:43 GMT, allbery@NCoast.ORG (Brandon S.
>>>>> Allbery KB8JRR) said: 

Brandon> ... the bug in /etc/movemail (rms can call it whatever he
Brandon> wants, in a real world system which *needs* security it's a
Brandon> bug) ...

Any system with an administrator who makes random programs from the
net suid root has very large security problems indeed.  Do you really
think it is possible for a programmer to guess every possible stupid
action of such a system administrator?