26th Sep 2002 [SBWID-5544]
COMMAND

	setgid - setuid

SYSTEMS AFFECTED

	All

PROBLEM

	Wietse Venema pointed  out  an  excellent  paper  on  the  setX/getX[id]
	semantics and its security implications on various type of systems.  All
	you ever wanted to know .
	
	"The August USENIX Security conference has a good  paper  that  examines
	in depth the semantics  of  UID  and  GID  setting  calls  for  Solaris,
	FreeBSD and Linux. The differences are quite remarkable."
	
	Setuid Demystified, by Hao Chen, David Wagner, UC Berkeley;  Drew  Dean,
	SRI International:
	
	 http://www.cs.berkeley.edu/~daw/papers/setuid-usenix02.pdf 
	
	
	

SOLUTION

	-