Re: LD_ hole (was Re: IFS hole?)

Howie Kaye (
Wed, 15 Dec 93 19:17:26 EST

This depends on the real uid being different from the effective uid.  If
your program does something like "setuid(geteuid())", then you lose this
protection.  If you then run another program, it will be running as root,
and won't look like a suid'ed program, just something running as root.  It
will then look at the LD_LIBRARY_PATH.

 -----------------------------Howie Kaye
Columbia University			hlkcu@cuvma.bitnet
AcIS UNIX Systems Group			...!rutgers!columbia!howie