Bugtraq mailing list archives

Re: Fix for ssh-1.2.27 symlink/bind problem


From: eivind () FREEBSD ORG (Eivind Eklund)
Date: Mon, 4 Oct 1999 10:35:02 +0200


On Sat, Oct 02, 1999 at 06:38:46PM -0400, Scott Gifford wrote:
I've put together a patch that lets ssh work around the OS bug that
allows bind to follow symlinks.

There isn't general consensus that this is an OS bug.  We (as in
FreeBSD) have installed a workaround consisting of blocking symlink
following for the case, but we have not yet decided if we should make
this permanent.

In my opinion, ssh is clearly the buggy party here; not following
symlinks in the OS is just a workaround to avoid buggy programs
causing problems.  We will only do this if we find that there are so
few legitimate consumers of the behaviour that we can change it
without problems - so far, we've only found one consumer, and it is
only of historic interest, being a part of FreeBSD itself (related to
/dev/log creation, IIRC) and only present in old versions.

Eivind.


Current thread: