Re: File table exhaustion patch

From: David G. Andersen (danderse@cs.utah.edu)
Date: 11/22/02


Date: Fri, 22 Nov 2002 05:40:05 -0700
From: "David G. Andersen" <danderse@cs.utah.edu>
To: Mike Silbersack <silby@silby.com>, freebsd-security@freebsd.org

Sheldon Hearn just mooed:
> On (2002/11/21 15:29), Mike Silbersack wrote:
>
> > HOWEVER, we're in a code freeze leading up to 5.0-release, and local DoSes
> > aren't a critical bug.
>
> Is that the official FreeBSD SO team viewpoint on local DoS
> vulnerabilities?

  Well, keep in mind that this isn't really a bad one - it doesn't
crash the machine, and it's moderately easy to identify the (l)user who's
doing it. I've actually not seen this happen maliciously, I've only
seen it happen by accident with buggy research code, some of it mine.
It's annoying when it happens, but there are a million things a local
user can do to be annoying.

  -Dave

-- 
work: dga@lcs.mit.edu                          me:  dga@pobox.com
      MIT Laboratory for Computer Science           http://www.angio.net/
      I do not accept unsolicited commercial email.  Do not spam me.
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message