OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Sep) 1998: Re: Serious Linux 2.0.34 security problem

Re: Serious Linux 2.0.34 security problem

Theo de Raadt (deraadtCVS.OPENBSD.ORG)
Tue, 30 Jun 1998 12:46:56 -0600

>   fcntl(0,F_SETOWN,p);
>   s = fcntl(0,F_GETFL,0);
>   fcntl(0,F_SETFL,s|O_ASYNC);
>   printf("Sending SIGIO - press enter.\n");
>   getchar();
>   fcntl(0,F_SETFL,s&~O_ASYNC);
>   printf("SIGIO send attempted.\n");
>   return 0;
> }

Well, that looks like one of the class of security problems described
by www.openbsd.org/advisories/signals.  Hasn't anyone else fixed those
problems yet?