> Here is the original message posted with permission, 10 points to > anyone who can spot the supposed flaw in the BSDI O/S with this. Looks to me as though exec() sets the UID on the process per setuid bits before it checks for arguments too long, and doesn't take care to undo this properly in that case. > BTW, anyone care to comment if this should be replicable across > platforms? Depends on where the bug came from. If it's one of those ever-since-V7 bugs it should be widespread; if it's a fumble-fingers mistake from BSDI it's probably not elsewhere. I'm sure everyone can imagine variations. I'm certainly going to test _my_ systems! der Mouse mouse@collatz.mcrcim.mcgill.edu