OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Sep) 1994: Possible Ultrix issue

Possible Ultrix issue

dan (dandan.com)
Wed, 20 Jul 1994 18:27:32 -0500 (CDT)

	I've just discovered that on Ultrix systems with X11 libs installed
yet lacking a /dev/xcons, /usr/lib/X11/xconsole can be used to destructively
overwrite any file on the system. To duplicate, set display to a working 
server, create a symbolic link from /tmp/Xconsole.log to the file to be 
overwritten, and run xconsole. The target file will be overwritten with a
single line error message concerning the nonexistance of /dev/xcons. 
	I believe the problem can be eliminated by creating a root 
read-writeable touchfile as /dev/xcons. 

	I havent had very much opportunity to play with this one yet, it may
have some other possibilities. 
	
	dan

-- dan cohn \ dandan.com