[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [SAGE] Looking for reuse: Script to change users UID, change group GID & re-permission files on large scale



>>>>> "Carlson," == Carlson, Scott <Scott.Carlson@schwab.com> writes:

Carlson,> This is perl, version 5.003 with EMBED				6

You realize that 5.003 has known buffer-overflow exploits?

And given that the exploits are known, keeping 5.003 on any system
where privilege escalation is a problem would be knowingly operating a
system in a dangerous way, and could be trouble for you if something
happened.

5.004 was systematically and thoroughly purged of buffer overflows,
and no buffer overflows have been discovered since then.  That was
roughly 8 *years* ago.  No excuse to be running known buggy software
on machines, at least not one that the attorney for the plaintiff
will buy. :)

-- 
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<merlyn@stonehenge.com> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!