Bug#334616: This doesn't seem to be a serious security problem

2005-10-21 Thread Javier Fernández-Sanguino Peña
On Fri, Oct 21, 2005 at 11:44:58AM +0200, Moritz Muehlenhoff wrote: > Hi, > while I agree that running yiff with lesser privileges is desirable > I can't see a RC security problem in this case. You can't crash > a system be reading from /dev, /proc or /sys, even reading from raw > hard disk devices

Bug#334616: This doesn't seem to be a serious security problem

2005-10-21 Thread Florian Weimer
* Moritz Muehlenhoff: > while I agree that running yiff with lesser privileges is desirable > I can't see a RC security problem in this case. You can't crash > a system be reading from /dev, /proc or /sys, even reading from raw > hard disk devices doesn't cause harm. If you know such a scenario >

Bug#334616: This doesn't seem to be a serious security problem

2005-10-21 Thread Moritz Muehlenhoff
Hi, while I agree that running yiff with lesser privileges is desirable I can't see a RC security problem in this case. You can't crash a system be reading from /dev, /proc or /sys, even reading from raw hard disk devices doesn't cause harm. If you know such a scenario please describe it, otherwise