26th Sep 2002 [SBWID-5544]
COMMAND
setgid - setuid
SYSTEMS AFFECTED
All
PROBLEM
Wietse Venema pointed out an excellent paper on the setX/getX[id]
semantics and its security implications on various type of systems. All
you ever wanted to know .
"The August USENIX Security conference has a good paper that examines
in depth the semantics of UID and GID setting calls for Solaris,
FreeBSD and Linux. The differences are quite remarkable."
Setuid Demystified, by Hao Chen, David Wagner, UC Berkeley; Drew Dean,
SRI International:
http://www.cs.berkeley.edu/~daw/papers/setuid-usenix02.pdf
SOLUTION
-