OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 1st quarter (Jan-Mar) 1997: Re: XDM bug

Re: XDM bug

Mr. ManX (mrmanphoenix.net)
Fri, 3 Jan 1997 19:24:35 -0600

/usr/X11/bin/xdm on my Slackware 96 system, /usr/bin/X11/xdm on my
Digital Unix system, and /usr/X11R6/bin/xdm on FreeBSD 2.1.5 are all not
subject to this problem.  All systems have the program not set-UID.

Mr. Man X
http://www.cuervocon.org
http://www.mybutt.com

On Fri, 3 Jan 1997, Steve "Stevers!" Coile wrote:

> On Thu, 2 Jan 1997, Angel Ortiz wrote:
> [...]
> > System: UNIX Ware systems with X
> >
> > Symptom:
> > /usr/X/bin/xdm is setuid
> [...]
> > Any way, please verify xdm setuid on your systems and please let the
> > bugtraq news group know if it exists on other systems.
>
> Red Hat Linux 3.0.3 (w/unofficial shadow password support) is not subject
> to this problem (/usr/X11/bin/xdm is not set-UID).
>
> --
>     Steve Coile           P a t r i o t  N e t      Systems Engineering
>  scoilepatriot.net      Patriot Computer Group        (703) 277-7737
>