[krbdev.mit.edu #8566] krb5_init_context() should detect set-uid-ness
Greg Hudson via RT
rt-comment at krbdev.mit.edu
Fri Mar 31 00:18:02 EDT 2017
I am a bit concerned that using the broken issetugid() on FreeBSD (and
NetBSD, if it's also broken there) could break legitimate uses of
Kerberos environment variables with httpd. Of course we can address
that, at least partially, by limiting our use of issetugid() to
platforms where it is known not to be broken.
More information about the krb5-bugs
mailing list