Re: Please unblock remctl 2.2-3 (security)

2007-02-05 Thread Luk Claes
Russ Allbery wrote: In internal testing, I discovered a long-standing logic bug in remctl (a client/server system for remote Kerberos-authenticated command execution) that would cause the server to treat a non-existant ACL file as authorization success, allowing any authenticated user to execute

Please unblock remctl 2.2-3 (security)

2007-02-03 Thread Russ Allbery
In internal testing, I discovered a long-standing logic bug in remctl (a client/server system for remote Kerberos-authenticated command execution) that would cause the server to treat a non-existant ACL file as authorization success, allowing any authenticated user to execute the command supposedly