OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: Re: Solaris 2.x chkperm/arp vulnerabilities

Re: Solaris 2.x chkperm/arp vulnerabilities


Subject: Re: Solaris 2.x chkperm/arp vulnerabilities
From: Craig Ruefenacht (ruefenacDIGSIGTRUST.COM)
Date: Mon Dec 06 1999 - 13:07:02 CST


Hi,

I verified that this bug exists in Solaris 2.7 with the latest security
and recommended patches too.

> Arp bug Verified for my Solaris 5.6 and 5.5.1 Installs.
>
> $ uname -a
> SunOS pangea 5.5.1 Generic_103640-26 sun4u sparc SUNW,Ultra-5_10
>
>
> # uname -a
> SunOS vapid 5.6 Generic_105181-05 sun4u sparc SUNW,Ultra-5_10
> #
>
> $ ls -l /etc/bin
> -rw-rw---- 1 bin bin 23 Dec 1 13:54 /etc/bin
>
> On both machines I could read bin:bin owned files as a regular joe user with arp

--
-------------------------------------------------------------
Craig Ruefenacht                             Systems Engineer
ruefenacdigsigtrust.com              Digital Signature Trust
(801) 983-4401                    http://www.digsigtrust.com/
-------------------------------------------------------------




This archive was generated by hypermail 2b27 : Tue Dec 07 1999 - 10:29:02 CST