Portable OpenSSH: Dangerous AIX linker behavior (aixgcc.adv)

Denise Genty genty at austin.ibm.com
Wed Apr 30 23:53:22 EST 2003


Damien Miller wrote:

> 5. Solution:
>
>         For the problem to be solved, the AIX linker must be changed to
>         only search system paths by default and never search the current
>         directory or user-specified paths for set[ug]id programs.
>
>         We consider this a serious flaw in IBM's linker, and urge
>         them to fix it immediately.  IBM, are you listening?
>

Hey man, we're listening -- I just need to figure out who to contact
about the problem.

--
Denise M. Genty
genty at austin.ibm.com    (512)838-8170 - T/L 678-8170
AIX Network Security Development
Server Division, pSeries






More information about the openssh-unix-dev mailing list