[Bug 787] Minor security problem due to use of deprecated NGROUPS_MAX in uidswap.c (sshd)

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Tue Feb 24 13:16:20 EST 2004


http://bugzilla.mindrot.org/show_bug.cgi?id=787





------- Additional Comments From openssh_bugzilla at hockin.org  2004-02-24 13:16 -------
I did not find as many examples of people (mis)using NGROUPS_MAX as you'd like
to believe.  Customers demanded more groups.  So it had to grow.

As I keep arguing - you DON'T want to know the maximum groups (in 99% of cases).
 You want to know the ACTUAL groups.  And I am doing what I can to find apps
like openssh that are broken, and help them to see the light.  Once it is fixed,
it's fixed.

Cheers.



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.




More information about the openssh-bugs mailing list