[Bug 787] Minor security problem due to use of deprecated NGROUPS_MAX in uidswap.c (sshd)
bugzilla-daemon at mindrot.org
bugzilla-daemon at mindrot.org
Tue Feb 24 13:16:20 EST 2004
http://bugzilla.mindrot.org/show_bug.cgi?id=787
------- Additional Comments From openssh_bugzilla at hockin.org 2004-02-24 13:16 -------
I did not find as many examples of people (mis)using NGROUPS_MAX as you'd like
to believe. Customers demanded more groups. So it had to grow.
As I keep arguing - you DON'T want to know the maximum groups (in 99% of cases).
You want to know the ACTUAL groups. And I am doing what I can to find apps
like openssh that are broken, and help them to see the light. Once it is fixed,
it's fixed.
Cheers.
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.
More information about the openssh-bugs
mailing list