Re: fetch extension - use local filename from content-disposition header



Ádám Szilveszter <adamsz@xxxxxxxxxxx> writes:
> You know, there are much bigger problems than that. For example the fact,
> that any vulnerability in fetch(1) or libfetch(3) is a remote root
> compromise candidate on FreeBSD, because the Ports system still insists on
> running it as root by default downloading distfiles from unchecked amd
> potentially unsecure servers all over the Internet.

Wrong. If you go into a ports directory and type 'make install clean'
as an unprivileged user, the only parts of the build that actually run
with root privileges are the final portions of the installation
sequence.

DES
--
Dag-Erling Smørgrav - des@xxxxxx

_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: fetch extension - use local filename from content-disposition header
    ... there are much bigger problems than that. ... compromise candidate on FreeBSD, because the Ports system still insists on ... running it as root by default downloading distfiles from unchecked amd ...
    (freebsd-current)
  • Re: Do we really need to worry about viruses
    ... > development company, and every one of the developers develops on ... and every one of them insists on running as root. ... worry about email viruses or click-thru vectors, ...
    (Debian-User)
  • I need to set up a site in a root, but FP wont let me
    ... I need to set up a site in a root, like http://www.mysite.com but FP INSISTS ... that I use a lower level folder name, ... Larry Woods ...
    (microsoft.public.frontpage.programming)
  • Re: Error saving html file
    ... not be allowed - unless an Administrator furnishes the password and insists. ... Vista prohibits writing files IN THE ROOT, ...
    (microsoft.public.windows.vista.file_management)
  • Re: root password and su (maybe)
    ... >> This is what sudo is for. ... If he insists on having root, ... > with a password-less sudoers file, you may as well run as root. ... much damage) and kill systems. ...
    (RedHat)