On Thu, Oct 12, 2000 at 01:24:11AM -0600, Lee Howard wrote:
> I tried it in vi, and it doesn't cause a problem.  There would have been at
> least 50M free at the time that pico was invoked.
> 
> My concern *isn't* that this file cannot be edited with pico.  I couldn't
> care less; I can use vi just fine.  However, my concern is that an
> unpriviledged user was able to down my system because of pico's lack of
> observance to the demand it would cause.
> 
> That seems like a security hole, to me.

But isn't there a DoS hole under Linux anyway? IIRC anybody who is
able to use all available memory (incl. swap) can bring the system down,
as the kernel will start to randomly shut down processes. That was true
for 2.0.x at least, I don't know whether that was fixed in the later
2.2.x or 2.3.x series - there was a lot of talk about it on the kernel
list once...
If I'm completely off target here, would someone please correct me? :-}

Regards,

Thomas
-- 
             "Look, Ma, no obsolete quotes and plain text only!"

     Thomas Ribbrock | http://www.bigfoot.com/~kaytan | ICQ#: 15839919
   "You have to live on the edge of reality - to make your dreams come true!"



_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to