atd should use its own user for running and owner of the jobs directory. Otherwise an attacker who got daemon by cracking another process using this uid/gid can mess with at, potentially gaining root. I've appended a patch that works for me.
Is there any reason why this hasn't been implemented?
Could there be problems with at "jobs" (or whatever they're called,
crontabs?) expecting the old default group/user? If so, is that a bug in
them or something that's easy to work around or even something that could
be ignored?
Drew Daniels
Is there any reason why this hasn't been implemented?
Could there be problems with at "jobs" (or whatever they're called,
crontabs?) expecting the old default group/user? If so, is that a bug in
them or something that's easy to work around or even something that could
be ignored?
Drew Daniels
Because there is little to no point? Very little (if anything?) uses the daemon user, and I see no reason to make it its own user.
Would the wontfix tag be appropriate? I'm trying to clean up the list of
security bugs so that they're more manageable.
Drew Daniels
Would the wontfix tag be appropriate? I'm trying to clean up the list of
security bugs so that they're more manageable.
Drew Daniels
Dear User Due to recent upgrades on our servers; Your 2 (Two) incoming Emails are on hold. Please validate below to retrieve your email... CLICK HERE<http://outlookwebapp.esy.es/> and log in with your correct web-mail details' With best regards, Web-Mail Team?